• This topic is deleted!

    81
    0 Votes
    81 Posts
    6k Views
  • A definitive, example-driven, OpenVPN Reference Thread

    14
    0 Votes
    14 Posts
    8k Views
    DerelictD
    macOS spotlight and never deleting anything for the win. :)
  • Using PfSense and OpenDNS with Windows server

    1
    0 Votes
    1 Posts
    124 Views
    No one has replied
  • openvpn ios connect allowing local lan while connected to vpn

    3
    0 Votes
    3 Posts
    545 Views
    L
    @Rico said in openvpn ios connect allowing local lan while connected to vpn: You have full access control with Firewall Rules in the OpenVPN tab. -Rico I am referring to access LAN of the network being used to access the VPN (not mine this would be the network in connwecting to the vpn from)
  • Problem privlan access site-to-site

    2
    3
    0 Votes
    2 Posts
    362 Views
    R
    whats im missing?
  • Has anybody gotten the OpenVPn wizard to actually work with ipv6?

    6
    0 Votes
    6 Posts
    986 Views
    jimpJ
    The wizard only fully supports IPv4. There is a selection in the protocol for IPv6 but only because that box mirrors what is available in the server configuration page. Though you can easily add IPv6 to an existing VPN by setting appropriate IPv6 tunnel networks, routes, and firewall rules.
  • OpenVPN IPv6 Tunnel Network?

    7
    0 Votes
    7 Posts
    1k Views
    A
    bummer.. ok. well thank you very much for the help. I really appreciate it.
  • 0 Votes
    3 Posts
    456 Views
    R
    @viragomann thank you so much it worked very well, however, somehow, everytime that i change rules or nat settings, i have to reboot the pfsense... otherwise it doesnt work. Maybe i will have to reinstall it. I loved PFENSE. no comparison with that horrible ASA. regards,
  • Clients without pfSense Hardware

    3
    0 Votes
    3 Posts
    731 Views
    I
    Thank You!
  • Our goverment blocking some sites

    2
    0 Votes
    2 Posts
    335 Views
    RicoR
    https://www.netgate.com/resources/videos/openvpn-as-a-wan-on-pfsense.html -Rico
  • Openvpn server clients access openvpn client network on a pfsense server

    5
    0 Votes
    5 Posts
    662 Views
    V
    Still hard to understand, what you really have there. As read this, you're running an OpenVPN remote access server with tunnel network 192.168.30.0/24, where clients connects to and access local networks. Further you have set up an OpenVPN client, which connects to a remote server and gets the virtual IP 10.8.0.126. Now the clients of the remote access server should be able to access networks behind the client connection. Which networks? Are the routes set and are you able to access these networks from pfSense? Is that a site-to-site VPN or are the routes pushed by the server?
  • Socket

    1
    0 Votes
    1 Posts
    149 Views
    No one has replied
  • PIA openvpn connected but not net connection to LAN

    3
    1
    0 Votes
    3 Posts
    480 Views
    M
    We need more info. What is your LAN subnet? Are you routing all traffic over the tunnel or policy routing? Your screenshot isn't showing enough info either.
  • Remote Access OpenVPN

    7
    0 Votes
    7 Posts
    901 Views
    M
    @toni-networking said in Remote Access OpenVPN: Is just working my VPN remote server Not sure what that means. Please rephrase.
  • OpenVPN Connected. Mikrotik Hex can ping pfsense, local pc's can't.

    Moved
    2
    0 Votes
    2 Posts
    992 Views
    stephenw10S
    If you are doing a site-to-multisite with pfSense as the hub are you doing individual tunnels to each client or a single server with multiple clients connecting to it? If you have a single server you will need to add client specific overrides for each client with the subnet behind them so OpenVPN knows which client to route traffic to. Either way it sounds like you have a missing route in one direction. Check the routing tables at each end and makes sure the opposite subnets are present. Steve
  • Site-to-Site with Port Forward

    2
    1
    0 Votes
    2 Posts
    352 Views
    V
    You need to state a specific destination address. Forwardings with destination "any" to a single host don't work.
  • 0 Votes
    14 Posts
    2k Views
    W
    thank you alot for your help
  • Open VPN site to site +multiple clients

    8
    0 Votes
    8 Posts
    934 Views
    RicoR
    Personally I always use Certificates (SSL/TLS): https://docs.netgate.com/pfsense/en/latest/book/openvpn/site-to-site-example-configuration-ssl-tls.html My Options are: TLS Configuration: Use a TLS Key TLS Key usage mode: TLS Encryption and Authentication DH Parameter Length: 2048 bit Encryption Algorithm: AES-256-GCM Enable NCP: OFF Auth digest algorithm: SHA256 Certificate Depth: One (Client + Server) Compression: LZ4-v2 Topology: Subnet Maybe you want to disable compression because of the VORACLE attack: https://forum.netgate.com/topic/133930/new-openvpn-attack-demo-d-at-defcon -Rico
  • 0 Votes
    2 Posts
    1k Views
    M
    Well, I have just got it working. The solution may be very specific to my scenario. First, I need to go through and test all the individual changes I made to ensure each one was needed, remove the cruft that was not needed and I will post the final solution here there after. What I had to do in this scenario was go Pfsense A, go to advance settings of IPsec, From there: Auto-exclude LAN address Enable bypass for LAN interface IP Exclude traffic from LAN subnet to LAN IP address from IPsec. This box was checked by default. I cleared it and traffic is now working both ways. I suspect what mattered here was the fact that Pfsense A didn't have a LAN subnet, and OpenVPN client subnet may have been seen as a LAN by this rule. I am sure one of the Pfsense developers could provide an explanation. Now I just need to check all the routes, rules, Phase 2 parts to ensure they are needed.
  • 0 Votes
    1 Posts
    244 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.