• Post Quantum Cryptography

    1
    0 Votes
    1 Posts
    218 Views
    No one has replied
  • OpenVPN routing problem from Office to Branch network

    3
    0 Votes
    3 Posts
    191 Views
    S
    @Sateetje I think I have found it. I had an allow all rule at the bottom of the rules on the LAN interface. In the rule I set the default gateway to a gateway group, look like this was the issue.
  • OpenVPN server with a different gateway (not default one)

    2
    0 Votes
    2 Posts
    160 Views
    V
    @leptdre What do you mean with "outbound traffic"? The upstream traffic from connected clients? If this you can simply policy route it like traffic on any other interface.
  • OpenVPN very slow after updating pfSense from 2.6.0 to 2.7.2

    1
    0 Votes
    1 Posts
    128 Views
    No one has replied
  • OpenVPN pfSense to pfSense (peer-to-peer) connected but not routing

    17
    0 Votes
    17 Posts
    797 Views
    V
    @jhg said in OpenVPN pfSense to pfSense (peer-to-peer) connected but not routing: It seems you need all of the following non-default settings Client System/General Setup/DNS Server Override ON As mentioned multiple times, I think, this setting affects pfSense itself only, as long as you have not enabled DNS forwarding in the Resolver. You still didn't mention if you have this. Anyway, it has no affect on a domains, which you have configured an override for. VPN Client/Tunnel Settings/"Pull DNS" This also has no affect on a domains, which you have configured an override for. So you don't need to set this for your purposes and I never suggested to enable this option. Custom firewall rule on OpenVPN interface to allow incoming traffic That's pretty plausible. pfSense is a firewall, all intended traffic needs a rule. Server DNS Resolver: add an ACL permitting the remote LAN to query the server's DNS resolver That's by design of Unbound (DNS Resolver). You need ACLs for all unknown source IPs. Some comments: If you use the wizard to create multiple VPNs you'll get duplicate firewall rules for incoming VPN traffic Also note, that the rule tab "OpenVPN" is in fact an interface group including all OpenVPN instances your are running, can be servers or clients. Hence rules, you add there are applied to all. For better separation you can assign interfaces to the OpenVPN instances. However, remember that rules on the interface group have priority over ones on a member interface.
  • 0 Votes
    1 Posts
    180 Views
    No one has replied
  • Failed to import openvpn profile in ios device

    3
    0 Votes
    3 Posts
    544 Views
    R
    @Gertjan Thank you for your response. I solved the issue by creating certificates by setting the digest algorithm as SHA245.
  • Multisite OpenVPN Set up , a good guide

    1
    0 Votes
    1 Posts
    104 Views
    No one has replied
  • ARP and DHCP and OpenVPN

    8
    0 Votes
    8 Posts
    407 Views
    T
    Yes, that was it. What I have settled on LAN = 192.168.0.1/24 VPN = 192.168.1.0/24 CIDR 192.168.0.0/23 "covers" them both perfectly I'm not quite sure what to do if I want another VPN. If I made it 192.168.2.0/24 I'd have to use 192.168.0.0/22 to cover both VPNs and the LAN, but now the Maximum Address is 192.168.3.254 -- so it "wastes" 255 IP addresses. But I'm not there yet and there's probably a better way to do it. Thanks for all your help.
  • 0 Votes
    4 Posts
    626 Views
    V
    @Enso_ I was talking about the firewall on the destination machine. To investigate the issue, sniff the traffic with packet capture on pfSense on the LAN interface and see if you get both, request and response packets.
  • OpenVPN errors with client on mikrotik

    5
    2
    0 Votes
    5 Posts
    255 Views
    M
    @viragomann Here is the mikrotik config: [image: 1726580334812-2ca5f715-8cd8-400a-8c3e-c29d9f1f833d-image.png] [image: 1726580361664-a9ba1797-f786-47d3-bba6-639dffdbc4c8-image.png] [image: 1726580393098-586386f7-6801-4f64-a484-159b42b242c0-image.png] I am just not sure regarding the IP's
  • 0 Votes
    3 Posts
    980 Views
    W
    Hey, In here I've decribed my work on this topic :) https://forum.netgate.com/topic/189447/openvpn-ssl-tls-user-auth-over-ldap/3
  • Server certificate expiring - Just want to check.........

    4
    1
    0 Votes
    4 Posts
    242 Views
    V
    @alanbaker Retaining the serial doesn't make sense here. But anyway, it would not have any affect to the clients. As well the private key is only used by the server for encryption and doesn't affect the clients. After reissuing ensure that the new certificate is assigned properly to the server.
  • Open VPN Client Router CUDY

    1
    0 Votes
    1 Posts
    112 Views
    No one has replied
  • OpenVPN Client Export and Shared Key Export functions missing?

    3
    1
    0 Votes
    3 Posts
    163 Views
    J
    @viragomann Thanks for the pointer. I've installed it now.
  • Unable to delete OpenVPN server and client definitions?

    2
    0 Votes
    2 Posts
    132 Views
    V
    @jhg Is there in interface assigned to the concerned OpenVPN instance by any chance? If so you have to remove it before.
  • Compression being pushed by pfsense?

    7
    0 Votes
    7 Posts
    620 Views
    S
    @viragomann Thanks. Changing the server settings to Decompress + Disable Compression does remove the compression mismatch messages. But my strange connectivity issue still persists even with this change, which tells me that the compression mismatch was probably a redherring to my connectivity/routing issue. Thanks for your help on the compression part!
  • Solved: OpenVPN and Certificate Revocation Lists

    2
    1
    0 Votes
    2 Posts
    488 Views
    A
    Replying to my own topic - I've missed something like I've thought : I was re-using an old List of revoked certificates. IT appears that the CRL ( Certificate Revocation List ) has an expiry date. Which is in no way visible in the GUI to be honest. When I've created a new list and applied it to the VPN, everything works as expected. The thing is that this becomes clear only when you go to create another CRL, to be honest GPT4 Solved it for me. [image: 1726137708188-7e545c7e-0e44-40ee-af81-4ca4cf9d714a-image.png] Please close the topic.
  • OpenVPN via (temporary) LTE/4G (with static IPv6)

    8
    0 Votes
    8 Posts
    407 Views
    S
    Problem has been solved by using a secondary pfSense instance on a VPS, thanks
  • 0 Votes
    6 Posts
    660 Views
    JKnottJ
    @Jung-Fernmelder said in How to distribute IPv6 adresses to OpenVPN clients with changing prefixes via SLAAC: How to add the network by name? As I said, this would have to go to someone who's more familiar with OpenVPN. However, the global address is only necessary if you are going through the VPN & pfSense to the Internet. If you're accessing only your local network ULA is fine. I wish ISPs wouldn't do things like this that break IPv6.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.