• Pfsense with OpenVPN package installed

    1
    0 Votes
    1 Posts
    220 Views
    No one has replied
  • 0 Votes
    3 Posts
    829 Views
    Z
    Hello. Thank you very much. Let me see if I got it right.. The forum is blocked because i am redirecting all my traffic viabAirVPN and i should create a bypass rule? If that's the thing, how I do that? I was able to setup my system following guides butnI might lack a lot of theory... About advanced networking i am a newbie. Thank you
  • Host can't reach hosts on other LAN connected via OpenVPN

    7
    0 Votes
    7 Posts
    849 Views
    RicoR
    Glad you have it working now. -Rico
  • TLS Error: TLS key negotiation failed to occur within 60 seconds

    7
    3
    0 Votes
    7 Posts
    1k Views
    M
    It works!! I think the error was the public IP, thank you !!!!
  • Decentralised VPN

    8
    1
    0 Votes
    8 Posts
    1k Views
    RicoR
    There is no limit for mesh or star. With lots of sites and traffic you just need beefy hardware. -Rico
  • OpenVPN through two pfsenses

    12
    3
    0 Votes
    12 Posts
    1k Views
    D
    Thank you very much for your help. I had to leave the office now...I will retry it on Monday and let you know. Thank you very, very much!
  • DSLite Workaround sort of

    1
    0 Votes
    1 Posts
    424 Views
    No one has replied
  • Connect Watchguard SSLVPN Client to pfSense OpenVPN server

    1
    0 Votes
    1 Posts
    633 Views
    No one has replied
  • PFSense & OpenVPN performance Issues

    6
    0 Votes
    6 Posts
    1k Views
    T
    @johnpoz 1 - When I've tried in my LAN the latency is 1ms. In my land (switzerland) you have never ever more that 20ms. (if you have a fiber connection it's about 1 - 8ms). Now the thing is ... even if SMB is designed for LAN, I've a throughput of 8Mb... even when I'm streaming films from my server. So when I and a couple of friends are looking a stream at the very same moment.. that's fullfilled. I don't expect to have 1Gbps over VPN... but from 1Gbps to 8mb/s... it's a lot.
  • OpenVPN and VLAN setup with Unifi

    5
    0 Votes
    5 Posts
    833 Views
    V
    SOLVED thanks to another thread on this forum ..it was actually the VPN client configuration in that I had to check "Dont Pull Routes" which did the trick. Thank you!!
  • 2 OpenVPN servers on one IP address

    Moved
    6
    0 Votes
    6 Posts
    887 Views
    stephenw10S
    Ok, yeah. So if you add a pass all rule on the OpenVPN tab it will break traffic coming from location two across the load-balanced OpenVPN pair. You need to either assign the remote access OpenVPN server and add the rules on the new interface tab created. Or add rules on the OpenVPN tab that catch only the remote access users by specifying the source subnet. Steve
  • Confused about OpenVPN client DNS queries on a MultiWan setup

    2
    0 Votes
    2 Posts
    337 Views
    RicoR
    https://www.netgate.com/resources/videos/openvpn-as-a-wan-on-pfsense.html -Rico
  • Openvpn error routing

    14
    3
    0 Votes
    14 Posts
    2k Views
    stephenw10S
    Assuming you have rules to allow it, login to the sever gui and check the OpenVPN tab in the firewall rules. Or the assigned interface tab if you have assigned the OpenVPN server as an interface. Steve
  • firewall rules on server

    2
    0 Votes
    2 Posts
    286 Views
    JKnottJ
    @trazom ???? The same way as you configured it. Fire up a browser and connect to pfSense. They're under Firewall > Rules.
  • Client to Server to Internet Client

    5
    0 Votes
    5 Posts
    857 Views
    M
    @gertjan yes your onto it ;) yes its tun, "IPv4 Tunnel Network" ---> 10.10.77.0/24 Do you policy-route this 'call-in' network also ? ive tried to set it as follows.. Firewall / Aliases /IP Network or FQDN --->> 10.10.77.0/24 (OpenVPN) Firewall / Rules / LAN Interface (LAN) "also tried the openvpn here too" Source > Single host or alias "OpenVPN" Gateway is set the expresssvpn with that set like this, when the phone is connected, its works, but the internet connection is still show as my wan ip, and not the expressvpn ip
  • 0 Votes
    1 Posts
    178 Views
    No one has replied
  • Access to LAN net behind pfsense from OpenVPN net

    4
    2
    0 Votes
    4 Posts
    900 Views
    H
    Yep, LAN net is double NAT'd - I'm now working with ISP for switching router to bridge. My net is: [image: 1551583408831-c15a2547-b459-4c5e-8722-b83f9f7cff6f-image.png] On VPS I have OpenVPN server + Zabbix (10.8.0.1). On pfSense I have Zabbix agent + proxy (10.8.0.2). Pfsense self-monitoring works fine (without proxy). I want to monitor some devices in LAN - 192.168.1.101. Now i've been stuck in settings - pinging LAN devices from OVPN interface is not work, but pinging pfsense LAN address works fine. UPD dev ovpnc1 verb 1 dev-type tun dev-node /dev/tun1 writepid /var/run/openvpn_client1.pid #user nobody #group nobody script-security 3 daemon keepalive 10 60 ping-timer-rem persist-tun persist-key proto udp4 cipher AES-256-CBC auth SHA512 up /usr/local/sbin/ovpn-linkup down /usr/local/sbin/ovpn-linkdown local 10.10.10.4 tls-client client lport 0 management /var/etc/openvpn/client1.sock unix remote <ip> 31194 ca /var/etc/openvpn/client1.ca cert /var/etc/openvpn/client1.cert key /var/etc/openvpn/client1.key tls-auth /var/etc/openvpn/client1.tls-auth 1 ncp-disable resolv-retry infinite route-nopull link-mtu 1601 remote-cert-tls server My goal is to set up Zabbix monitoring from VPS (IP 10.8.0.1) of devices on the LAN network (IP 192.168.1.101) through a proxy installed on pfSense router (IP 10.8.0.2). Now zabbix says "Timeout while connecting to "192.168.1.101:161"." In the diagnostics tab of the pfsense router in the ping section i can successfully ping pfsense itself: 192.168.1.1 from 10.8.0.2, but 192.168.1.101 from 10.8.0.2 fail: packages are lost somewhere
  • 0 Votes
    2 Posts
    531 Views
    E
    @eric-marshall I guess that was just way TL/DR. Sorry Guys.
  • PIA VPN removes stealth mode at GRC Shieldsup

    8
    0 Votes
    8 Posts
    2k Views
    S
    Thanks for the info guys
  • Only first IP connected have acces to network

    6
    0 Votes
    6 Posts
    766 Views
    GertjanG
    @artware said in Only first IP connected have acces to network: Certificate are different In that case, you could switch to : [image: 1551452935790-3f385396-4483-40f0-a99b-7a9e484c020a-image.png] De-select Duplicate Connection. Firewall rules ?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.