• Restrict RA user traffic

    3
    0 Votes
    3 Posts
    502 Views
    S
    I setup network type as "net30" instead of "subnet" and all works. Thank you, you can close the thread.
  • pfsense Openvpn behind existing network

    9
    0 Votes
    9 Posts
    956 Views
    B
    Solved: Edit Advanced Outbound NAT Entry: LAN interface Protocol Any source: Any dest: lan network Translation: address: Interface Address wofks perfect! Thanks!
  • Assigning Specific IP's to OpenVPN Clients

    4
    0 Votes
    4 Posts
    469 Views
    T
    Thank you @Rico and @netblues - I really appreciate the help.
  • 0 Votes
    2 Posts
    912 Views
    RicoR
    Show your OpenVPN Config and Firewall Rules (Screenshots). -Rico
  • troubleshooting LDAP authentication

    15
    0 Votes
    15 Posts
    2k Views
    adamwA
    LDAP browser tool helped a bit and allowed me to see a more specific error: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C0903A9, comment: AcceptSecurityContext error, data 52e, v1db1] After a bit of research I've managed to connect using account@domain.co.uk format in "Bind credentials" username. This might be worth adding to the pfSense-LDAP troubleshooting guide.
  • OpenVPN service not working with PfSesne 2.4?!

    14
    0 Votes
    14 Posts
    4k Views
    RicoR
    You want to use self signed Certs with OpenVPN, not from any other CA! -Rico
  • bandwidth consumption

    Moved
    2
    0 Votes
    2 Posts
    416 Views
    stephenw10S
    You may be able to do that using reneg-bytes in the custom options field. It depends how the client authenticates. If they have to enter a password, and the client does not retain it, they would need to reenter the password after the specified number of bytes. That's a sum of bytes up and down. Steve
  • OpenVPN client shows as connected after reboot, but no internet

    4
    0 Votes
    4 Posts
    570 Views
    KOMK
    System logs? OpenVPN logs?.... "No Internet" isn't a particularly helpful description. Can you ping 8.8.8.8 for example? What error messages are returned to you, if any? For example, if you use a web browser to go somewhere, what specific error does it give you? Timeout? Can't resolve address? etc etc.
  • slow openvpn - windows only client

    2
    0 Votes
    2 Posts
    358 Views
    JKnottJ
    First off, keep upper and lower case straight when discussing bandwidth and speeds. For example, B = bytes and b = bits. Also, a 140 mb, that's millibit connection which would be damn slow. Perhaps you meant Mb, which would be a decent bandwidth. Also, do your Internet connections have symmetrical or asymmetrical bandwidth? It's often asymmetrical, which means you're going to be limited by the uplink bandwidth at both ends. Now you say 100 kbps. Is that supposed to be bits or bytes? If bytes, then it works out to a 800 kb/s, which is a typical value for some ADSL uplinks.
  • OpenVPN Site-to-Site fully broken after upgrade from 2.3.5p2 to 2.4.4

    6
    0 Votes
    6 Posts
    881 Views
    L
    After a long time we decided to try "second servis" upgrade from pfSense 2.3.5-p2 to 2.4.4-p3 on our remote offices. Everything went fine, so there is a little survey: OpenVPN site-to-site (shared key) tunnel has so called "dynamic" gateway in 2.4.x on client side, which is created automatically on the system startup. So if your old version has a manually created VPN gateway (routes to headquarter not included in OpenVPN config...), you have to remove this gateway before upgrade. My best practice was backup old configuration, upgrade, login to the upgraded pfSense and completely remove the old OpenVPN client and his TUN interface. Then I created new OpenVPN client. VPN gateway was created by system and a I could set up required routes again.
  • 0 Votes
    6 Posts
    11k Views
    havastamasH
    Its my home network. Sometimes i would play with my Xbox far away from home - im travelling much. With tap mode, remote stream/play/power-on works well, and i cant get it to work with tun mode. But i would not run another service just for my phone - but i have no choice..
  • Routed Error: - impossibly lacks ifp

    3
    0 Votes
    3 Posts
    1k Views
    R
    @Gil Hi, How did you solve this problem? I upgraded from 2.4.4-RELEASE-p2 to 2.4.4-RELEASE-p3 and started having the issue after a couple of days. Please share your solution.
  • OpenVPN on wan interface PPPoE

    2
    0 Votes
    2 Posts
    937 Views
    N
    @vladagri When setting up vpn server, is the pppoe up? I just tried to setup a new vpn server listiening on pppoe interface and worked with no issues
  • OpenVPN log - log userids?

    8
    0 Votes
    8 Posts
    7k Views
    C
    @johnpoz Hi JohnPoz! any chance that you could share "picture 3" again? The pic was In regards to filtering the pfsense gui log for vpn user logins. (old thread)
  • Connected but can not Access Internet & pfsense

    4
    0 Votes
    4 Posts
    505 Views
    RicoR
    Sure you can, I have 50 OpenVPN Instances up and running. But you need to use unique tunnel networks per Instance. -Rico
  • SG-3100 Site to Site VPN dies under heavy load

    7
    0 Votes
    7 Posts
    951 Views
    U
    Thanks for posting this. I was having the same issue with hardware crypto enabled on my SG-3100. Disabling seems to have resolved the issue though it certainly hasn't helped my CPU load.
  • [Solved] Can't route LAN through OpenVPN

    15
    0 Votes
    15 Posts
    1k Views
    N
    I've reset my conf and started all over again and now it seems ok.... Don't know what was wrong though. Thanks you all for you help
  • 0 Votes
    2 Posts
    511 Views
    B
    This is one of many reasons I dropped pia and nord. Either way I suggest reading up on the remote host command https://openvpn.net/community-resources/reference-manual-for-openvpn-2-4/
  • Change OpenVPN interface name

    2
    0 Votes
    2 Posts
    236 Views
    DerelictD
    You don't. No more than you change igb0. They are created in order, encompassing servers and clients. ovpnc1, osvps2, ovpns3, etc.
  • OpenVPN with FreeRadius 2FA

    5
    0 Votes
    5 Posts
    1k Views
    W
    @Derelict That was what I was missing.. Thanks for the help.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.