• 0 Votes
    7 Posts
    666 Views
    L
    Will do, in the mean time I got something more stable using limiters on in and out at half our DSL capability. Seems like when the link is saturated, the copy get frozen and not when the limiters are reducing. Might very well be due to failover of our SDSL WAN to ADSL second link activates (automatically in suppose due to poor ping)
  • OpenVPN with gateway group means internet access not working

    2
    0 Votes
    2 Posts
    272 Views
    RicoR
    https://www.netgate.com/resources/videos/advanced-openvpn-on-pfsense-24.html Multi-WAN Tactics starting at around 40:05min. -Rico
  • My CA Authority create blank CA User

    7
    0 Votes
    7 Posts
    670 Views
    R
    I think I touch something but I do not know exactly what. But when this happens it's better to start again :). thanks!
  • remote access client users > different VLANs

    4
    0 Votes
    4 Posts
    591 Views
    NogBadTheBadN
    FreeRadius and hand IP addresses (framed) out that you can use in firewall rules for the clients, I do it with IPsec so I can access everything and friends can only access the internet. Sort of pointless if all the users PCs the LAN side of pfSense are all on the same subnet. "andy" Cleartext-Password := "XXXXXXXX", Simultaneous-Use := "1", Expiration := "Apr 11 2027", NAS-Identifier == strongSwan Framed-IP-Address = 172.16.8.4, Framed-IP-Netmask = 255.255.255.0, Framed-Route = "0.0.0.0/0 172.16.8.1 1"
  • openVPN error unrouteable control packet received

    2
    0 Votes
    2 Posts
    177 Views
    RicoR
    Give an idea about your configuration and post the full log as text not picture. -Rico
  • PIA OpenVPN setup "Don't Pull Routes"

    pia openvpn gateways
    5
    0 Votes
    5 Posts
    3k Views
    N
    Thank you for your reply. When I check the widget, it only shows me the default gateway WAN_DHCP and does not show the openvpn gateway as a choice.
  • [Solved] Reach other VPNs thru Remote Access VPN

    3
    0 Votes
    3 Posts
    398 Views
    H
    @viragomann "Second" P2 is the key word Solved, Thank you very much
  • Automatic Switching of OpenVPN Client Interface

    1
    0 Votes
    1 Posts
    255 Views
    No one has replied
  • Openvpn site to site Problem

    7
    0 Votes
    7 Posts
    665 Views
    M
    @vidarne77 said in Openvpn site to site Problem: Reason for the Manual nat/was as for at main site it is needed for getting the right clients and servers over the proper vpns and vlans, atm you are right it is not needed for the basic setup so is at the offsite. (old habits setting it to manual) Glad it's working. Although just to throw it out there again, if you have access to both firewalls you don't need any NAT's for communication. All you need is routing and the firewall rules to allow the traffic. If you needed to add NAT's to get traffic flowing that tells me there are routes missing. By NATing, you lose granular auditing functionality, which may or may not be a concern for you. Personally, I always like to know exactly what is connecting to what. If you post your configs, we can offer more targeted info.
  • my site is not opening unless i use vpn what may be the reason ?

    2
    0 Votes
    2 Posts
    265 Views
    johnpozJ
    Trying to understand your problem here - your saying if you route traffic out a vpn, you can not load that site? What does that have to do with pfsense? They prob just block your vpn service.. Just like forums here blocks many vpn IPs.. What IP are you getting when you route through a vpn.. Is prob on a shitton of black lists..
  • SSL3 error

    4
    0 Votes
    4 Posts
    673 Views
    B
    @johnpoz I am certainly not an expert with pfnonsense... I solved my issue by moving to a 2.4.4 release. I was running on an old piece of hardware (32bit/2.3.x). I was trying to use OpenVPN client on PFSense to connect to ExpressVPN. It was clear in the logs that SSL3 was being used in the negotiation and the cert verify was failing as a result. Not an issue on 2.4.4. I am used to enterprise networking products where there is a clear documented way to control those settings client or server. I assume you are talking about OpenVPN server custom settings. I am not running OpenVPN server. Thanks!
  • Pfsense openvpn to openvpn with Unraid

    12
    0 Votes
    12 Posts
    2k Views
    RicoR
    Glad you have it working. -Rico
  • OpenVPN inbound DNAT/Port-Forwarding

    1
    0 Votes
    1 Posts
    292 Views
    No one has replied
  • Another 'can't ping lan from VPN' scenario

    6
    1 Votes
    6 Posts
    558 Views
    RicoR
    Glad you have it working again. -Rico
  • Dual routing from OpenVPN server to Client Internet

    14
    0 Votes
    14 Posts
    1k Views
    L
    @derelict said in Dual routing from OpenVPN server to Client Internet: Negative. The moment you assign the interface the VPN breaks. THEN you have to stop and start the server process. Client or server. Does the same thing. Show me in the manual where it says not to assign an interface to an OpenVPN server. You are right. It worked. Many thanks.
  • Can You Connect Unraid to Pfsense??

    1
    0 Votes
    1 Posts
    253 Views
    No one has replied
  • How to send specific traffic to WAN rather than VPN

    2
    0 Votes
    2 Posts
    293 Views
    V
    Yes, if you have checked "Don't pull routes" like it is shown in the tutorial, just add a firewall rule for that traffic (source = the two laptops) and leave the gateway setting at its default. Place this rule to the top of the rule set, so that it matches first.
  • openvpn customer information

    3
    0 Votes
    3 Posts
    420 Views
    S
    grateful, but it does not help me yet. I just want to get the cadastral information of my openvpn clients. the suggestion given brings everything (usable and revoked) and would have to be done one by one. Understood ?
  • How to config pfSense as OpenVPN server in DMZ?

    2
    0 Votes
    2 Posts
    1k Views
    P
    @philip2019 I'm not sure, finally it worked. It can't be test in the Lan inner in my situation, I can't ping my Wan public IP address from inner lan PC when it set a DMZ, I have to use another Internet connection to ping the Modem ip address. because the modem(router, Bell hub 2000), set a inner PC as DMZ, so in this pfSense server (as DMZ PC in Bell router), should allow ping in Wan interface, it's a simple firewall ruler, this help me know only another Internet connection can easy get the DMZ. other thing almost same with some guide in Youtube or web article, the only change is configuration will show the DMZ pfSense server Wan ip address as remote address(it also a Lan ip address), it impossible be visited for the Lan ip reason, change this IP to public IP address can be OK.
  • Strange behavior. IP ending with .2 works, ending with .3 not.

    openvpn
    8
    0 Votes
    8 Posts
    900 Views
    M
    No there were not. I have deleted everything related to the RoadWarrior Server now and recreated it with another cipher, but same settings/TunnelNetwork/Buffer/Rules. It seems to work now. Could it be that pfSense sometimes doesn't activate rules unless you recreate them? It felt like that, though I dont really know why it didn't work and now works.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.