• OpenVPN Cannot Browse LAN

    3
    0 Votes
    3 Posts
    380 Views
    T
    @JKnott Thanks. I used the ip addy and user authentication.
  • Changing setting to force all traffic through VPN

    2
    0 Votes
    2 Posts
    370 Views
    RicoR
    You do not need to force all traffic through the VPN to reach your Domain Controller / AD. -Rico
  • Wierd OpenVPN client behaviour causing disconnections

    14
    0 Votes
    14 Posts
    1k Views
    T
    @Grimeton said in Wierd OpenVPN client behaviour causing disconnections: Networking issues, followed by an ICMP package containing proto or port unreachable. ICMP package coming from me out to the server or vice versa? @Grimeton said in Wierd OpenVPN client behaviour causing disconnections: Networking issues causing OpenVPNs internal timer to timeout and disconnect/reconnect. What should I do in such case? EDIT: I've noticed that it usually happens when one of the VPNs in the VPN group (of 2) is going down (for maintenance or whatever) and because both/all of them are marked as Tier1 it may cause such reconnection attempts...on the other hand that's why we have VPN groups and Tier priority LOL
  • Constant disconnections and "Restart pause" in the system logs

    9
    0 Votes
    9 Posts
    852 Views
    T
    @Pippin According to NordVPN guys, the cipher thing is not an issue and their servers also support GCM. The fact that my choice of SHA512 is not recognized/mentioned in the logs is wierd though... @Pippin said in Constant disconnections and "Restart pause" in the system logs: Also, showing a fragment of the log doesn't help. It's not a fragment. It's the majority of it and it just repeats itself from time to time.
  • OPEN VPN Works for some user and other nor

    7
    0 Votes
    7 Posts
    972 Views
    RicoR
    Sniff traffic on the pfSense side to check if the client can even hit your OpenVPN server. -Rico
  • Open VPN issue...sorta fixed, but need an explanation

    1
    0 Votes
    1 Posts
    251 Views
    No one has replied
  • [SOLVED] Public IP address has not changed

    3
    0 Votes
    3 Posts
    534 Views
    S
    @Gertjan you are correct. I will just set everything to go thru the tunnel and be done with it. Thanks for pointing these things out.
  • Slow(ish) OpenVPN on site to site VPN.

    1
    0 Votes
    1 Posts
    301 Views
    No one has replied
  • Help Verify My Setup

    1
    0 Votes
    1 Posts
    281 Views
    No one has replied
  • OpenVPN Client Specific Overrides routing for a single user

    8
    0 Votes
    8 Posts
    1k Views
    J
    @Pippin no I have several (12) user each one with a specific routing...
  • Bridge OpenVPN (preshared Key) with Pfsense & Router Robustel

    1
    0 Votes
    1 Posts
    449 Views
    No one has replied
  • 0 Votes
    3 Posts
    757 Views
    G
    I'd also investigate a MTU mismatch etc... Here's my (potentially flawed) logic: Server on Side A has larger MTU than Server on Side B. (I assume you copy server to server) Initializing the transfer from Site (B) I can copy FROM a file server on Server (A) with roughly 20MB/sec which is great. I assume the server on Side B requests a small packet size... (Maybe Path MTU Discovery) Initializing the transfer from Site (B) I can copy TO a file server on Server (A) with roughly 20MB/sec which is great. The server on Side B sends data packets that are smaller than Server A maximum accept size. Initializing the transfer from Server (A) I can copy FROM a file server on Site (B) with roughly 20MB/sec which is great. The server on Side B will only send small packets (or packets that are smaller than what Server A can receive) ...but Initializing the transfer from Server (A) I can copy TO a file server on Site (B) with only roughly 8MB/sec Server A doesn't know that Server B can only receive small packets. The Firewall (VPN endpoint) on Side B now has do extra work breaking up large packets into smaller ones - which Server B can accept. So my guess would be fragmentation etc... MTU can be set on Host interfaces, too ... You could try reducing the MTU Size on Server A network interface. Also have a look at the pfsense option (Remove DF bit) https://www.reddit.com/r/sysadmin/comments/2mt3jc/reducing_mtu_value_to_fix_slow_cifssmb_over_vpn/
  • Windscribe pfsense guide

    windscribe openvpn setup netflix vpn
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • [Solved] OpenVPN on Opt1 problem

    3
    0 Votes
    3 Posts
    421 Views
    S
    Ah, got it. I knew I was missing something simple. Thanks!
  • 0 Votes
    9 Posts
    2k Views
    johnpozJ
    @ddbnj said in Cannot access beyond router via OpenVPN: 10.8.0.0 0.0.0.0 255.255.255.0 U 0 0 0 tun0 Yeah that would dick it up ;) Glad you got it sorted! Told you it wasn't pfsense ;) hehehehe The trick is getting the person to clearly see that themselves... Which is why the sniff proves to the user, hey pfsense is doing what its suppose to be doing... Have to look elsewhere..
  • Pfsense Openvpn access in LAN

    8
    0 Votes
    8 Posts
    1k Views
    johnpozJ
    If you do run your vpn server downstream, you can host route on devices on your local network that you want to create traffic from to your remote vpn clients.. Its not all that hard to do, depending on the such restrictions you might have on the actual local client.
  • No LAN access for 2nd client/user

    9
    0 Votes
    9 Posts
    844 Views
    B
    @handleric I think that fixed the issue. Thank you!! This has been driving me nuts!
  • Client VPN Routing Problem

    5
    0 Votes
    5 Posts
    685 Views
    H
    Hello, Over the past few days i've been doing a lot of research trying to remediate this issue and it seems there are a dozen or more threads for this same issue, is anybody from the development team investigating this?
  • ExpressVPN down on pfsense 2.4.4

    9
    0 Votes
    9 Posts
    3k Views
    U
    @akkiz Not got express vpn, but sounds like phill simply re-created or selected his openvpn certificates and downloaded a fresh copy and used them instead. pfsense can be tricky one wrong setting or one wrong copy and paste of a set of certifcation and it won't work, always best to take your time and re-read the guides and double check your settings, am still making mistakes time to time.
  • Astrill OpenVPN Client setup

    2
    0 Votes
    2 Posts
    632 Views
    U
    Hi this probably won't be as much help but I did try Astrill VPN a few months ago, did ask tech support but they told me pfsense was not supported and they had no future plans to do so. Instead they support merlin firmwares on Asus routers like the Asus 86u (just make sure you access it via 192.168.1.1 router address and not their asus logging website!) Astrill have a applet which works on Asus router (merlin supported) which support port forwarding. It does work stable and well imo. If you are good enough with networking and pfsense you could download the openvpn files and open the files via notepad and see the server addresses and ports and details and perhaps use this in pfsense. I do not have astrill anymore and did not try this when I had it though but was going to use mullvad or nordvpns pfsense guide and just input astrills server address and port number and use astrill certs and files instead. Its a shame Astrill does not support pfsense properly, but I guess they wished to go via commerical routers like Asus and netgear instead.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.