• openvpn issues

    6
    0 Votes
    6 Posts
    3k Views
    P
    That definitely sounds frustrating. Since you're seeing both certificate generation errors and TLS key export problems, it feels like there may be multiple bugs involved rather than a simple configuration mistake. If anyone else is testing 25.11, it would be interesting to know whether these OpenVPN issues appeared after a fresh install or only after upgrading. Sometimes checking the periodo entre datas between snapshots and recent fixes can also help identify whether a regression was introduced in a specific build.
  • OpenVPN client certificate issue

    1
    0 Votes
    1 Posts
    724 Views
    No one has replied
  • OpenVPN Log

    3
    1
    0 Votes
    3 Posts
    2k Views
    UnoptanioU
    @Gertjan ok thanks
  • OpenVPN with ipv6 delegated prefix

    35
    0 Votes
    35 Posts
    14k Views
    T
    Okay, I've moved to my new house which is not on comcast so I don't have the ability to test this in production any more. Hopefully someone else picks up my patches.
  • OpenVPN - make Client Specific Overrides persistent after reboot

    2
    0 Votes
    2 Posts
    1k Views
    GertjanG
    @eegclbugs said in OpenVPN - make Client Specific Overrides persistent after reboot: with a script and not with the GUI for each user individually. You're already close to the answer ^^ If you found this : [image: 1779291236149-99d2d10a-8edf-4b54-9294-543f6218e683-image.png] you actually use this : [image: 1779291275273-b52bf3f7-9b15-456a-b197-75f3670153cd-image.png] That file can be found here : /usr/local/www/vpn_openvpn_csc.php Read that file (it's a script, world's most known : php) The bottom part is what your browser shows you. The top part is where the user's input (the pfSense admin), is validated, stored in the "one and unique pfSense config file" and you also find where the scs file are created etc. So ... if your script can use this script as a source, model (etc) you'll have the best of both worlds : Your script adds/edit/whateber the scs file. The - your - info is stored into the "one and unique pfSense config file" so when pfSense restarts, everything is setup according to its "one and unique pfSense config file" info. And you can still use the GUI to look/edit/delete things. Btw : this is a 'how I would do it solution'. Commanding pfSense from the command line without doing it the 'pfSense' way is generally a bad idea.
  • ifconfig option in OpenVPN server config for Peer to Peer necessary?

    3
    0 Votes
    3 Posts
    2k Views
    S
    @Gertjan said in ifconfig option in OpenVPN server config for Peer to Peer necessary?: Then restart the openvpn server (client) and see what happens. That's one idea I had, but since the traffic is routed to the remote side via IP 10.0.0.2 this will break my connection. It's a router to router connection, but this must also possible with the "Remote Access" mode? So whats the exactly benefit of the peer to peer Mode?
  • OpenVPN CVE-2026-40215 | will CE 2.8.1 also received the update to 2.6.20?

    12
    0 Votes
    12 Posts
    5k Views
    S
    It's now fixed in Plus and CE: https://forum.netgate.com/post/1242673
  • openvpn-client-export remove persist-key from regular export (deprecated)

    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    It's only ignored, not a fatal error, so it's not critical to remove yet. They do not have a timeline for its removal, so there's no hurry to change it at the moment. We usually drop options to "legacy" when they cause a failure or otherwise have a negative impact. Leaving them in place as they are now increases the compatibility of the generated configuration files with a wider range of OpenVPN client versions.
  • OpenVPN issue when unautorized login attempt

    12
    1
    0 Votes
    12 Posts
    5k Views
    GertjanG
    @Autourdupc said in OpenVPN issue when unautorized login attempt: One side, external : LAN2 with NAS2 -> Freebox (router) -> WAN Other side, office : LAN1 with NAS1 -> pfsense (router) -> Freebox (router) -> WAN Purpose : NAS1 sends backup to NAS2 Replace 'Freebox' with 'Livebox' and you have exactly my same setup. I backup my work Synology diskstation to my home Syno diskstation, using Hyper Backup on one side (work) and the counterpart 'The Vault' at the home side. Since I have fiber at home and at work, this has became a usable option. Renting 10 Tera somewhere was way more expensive. Previous upload speeds (VDSL) made this nearly impossible anyway. I used OpenVPN in the beginning ... but then I started to think : the communication channel is 'ssh' and the distance isn't that far. SSH means : traffic is TLS encrypted. The data copied are already encrypted Macrium Reflect backup files. Do I really need an encrypted VPN channel over an encrypted channel with data already encrypted ? Btw : the data is company related (a hotel) and we don't store private client info, maybe just their name, and their bills and so on. Since I stopped using VPN, my backups always terminate every night, and it takes some 60 minute s or so to transfer something like 250 Gbytes. I do use OpenVPN for remote admin access. Just UDP. Never had any issues with that. The only 'VPN' "errors" I see are these : [image: 1778046306704-e46a8a08-5bbd-4e60-8c34-9876e6a2fd1e-image.png] and these are, imho, just packets from scanners trying. The OpenVPN isn't restarted.
  • Renegotiation Time with MFA

    1
    0 Votes
    1 Posts
    691 Views
    No one has replied
  • Services over VPN work on one laptop yet not an other

    4
    0 Votes
    4 Posts
    2k Views
    C
    @Gertjan Thanks, I appreciate your research. That was a while ago when I got services working as I expected. Once I was confident, I understood what the expected SMB handshake should look like, I could see there was a ton of congestion, and the packets were just getting dropped. I don't remember exactly what I uninstalled or disabled to improve SMB traffic, however. Assigning the ovpns1 to an interface is an interesting choice. I believe configuring firewall rules on the OpenVPN tab may achieve a similar result.
  • OpenVPN Crash after update

    8
    0 Votes
    8 Posts
    4k Views
    P
    @Gertjan Are there by any chance any other logs I can check?
  • 0 Votes
    15 Posts
    6k Views
    I
    After the adjustment, it has been working well for some time now, and the issue appears to be resolved.
  • Configure pfSense with Microsoft MFA for VPN

    1
    1 Votes
    1 Posts
    781 Views
    No one has replied
  • pfSense OpenVPN multiple servers crash

    1
    1
    0 Votes
    1 Posts
    709 Views
    No one has replied
  • OpenVPN Gateway Issues

    3
    1
    0 Votes
    3 Posts
    2k Views
    K
    i have the exact same problem as you do and pfsense has set it to dynamic and grayed out the option to change it to static and netgate support wont help at all
  • ExpressVPN CA Certificate Expiration

    expressvpn
    23
    2 Votes
    23 Posts
    11k Views
    W
    @Gertjan Previously, swapping locations would sometimes still get TLS errors, but that was due to not separating the CA authorities, like you did in your photo. Thanks for capturing that. Now, as of 11 April at least one .ovpn file (chosen at random) downloaded without the second CA. Fortunately, by offering just the CA 3 that matches your photo, it all works again. The authority now expires in 2124, and certificate 2066 as you documented. With that, reviewed all settings, and that finally resolved the TLS errors/cert expirations/or connection failures. ExpressVPN / pfSense immediately connect. Everything is looking great. ***While at it, another major company has Certs expiring this summer too (related to secure UEFI keys for booting). So, ensure auto update / latest updates are on for systems/devices before the expiration this summer. Auto update seems to be the preferred route.
  • OPEN VPN MULTISITE ON HIRING PFSENSE CLOUD

    4
    1
    0 Votes
    4 Posts
    2k Views
    N
    @Manhbkas270495 Read the documentation https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/index.html And read about iroute. This is what you need
  • VPN access for specific user only

    14
    0 Votes
    14 Posts
    6k Views
    O
    @Gertjan Ah haha Noted. And thank you so much for the help.
  • MS Azure AD/Entra as auth server for OpenVPN

    8
    1 Votes
    8 Posts
    5k Views
    S
    @sgw this is the way to do it. And no it's not scary.
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
Privacy Policy · Cookie Policy