• Unable to reach LAN IP after connecting to openvpn

    48
    0 Votes
    48 Posts
    14k Views
    johnpozJ
    So you had messed with your outbound nat like I brought up way earlier in the thread.. If your outbound nat is automatic when you run through the openvpn wizard it will add your tunnel network to the nat.. Did you switch to automatic, or did you create some nat - mind posting your outbound nat screen..
  • can not ping access anything behind openvpn

    22
    0 Votes
    22 Posts
    2k Views
    C
    @onyxfire reason I set it to hybrid is because the few youtube videos posted for xbox and Double Nat Type for pfsense said you need to set it for this and then set a bunch of ports but it never helped in the end.. ill worry about that later... as for the alias ah cant be bothered I just have xbox one and 360 and a ps3 but only xbox one hooked up as for the wizards I see it now I didn't see it before.. also with dyslexia I miss read words.. like "mother" I sometimes read as "hello" reason why I need to re read things 3 4 times or so sometimes bad case I have.. and reason I was using cell phone was easier for me to take to tim hortons or home depot and test the OpenVPN then taking the laptop in the store and then I installed Ping program so I could see if I could ping my local network least then I could test with a laptop.. as I originally wanted to do Remote desktop server1.example.com remote desktop server2.example.com but was told I idiot no point In setting it up you need vpn as I been doing like 3389 port for server 1 3391 port for server 2.. and I didn't wanna do port forwarding anymore I wanted to connect like I do at home or least have reverse name look up I think its called like remote desktop server1.example.com @johnpoz and sorry I didn't see the wizard you mention ill try again.. I miss read the screen..
  • Connect to L2L Network over VPN

    1
    0 Votes
    1 Posts
    346 Views
    No one has replied
  • Require clients to update?

    5
    0 Votes
    5 Posts
    910 Views
    jimpJ
    You could enable a feature on the server side that requires OpenVPN 2.4 and then older clients would fail to connect. Harsh, but that's about the only way you could require a minimum version from the client end.
  • [SOLVED] Unable to open port from OpenVPN

    2
    0 Votes
    2 Posts
    440 Views
    SipriusPTS
    It was a bad source configuration at my VLAN over WAN, I had WAN instead. Thanks anyway!
  • OpenVPN Client: No internet

    1
    0 Votes
    1 Posts
    410 Views
    No one has replied
  • After Setting up OpenVPN I get reload errors

    2
    0 Votes
    2 Posts
    483 Views
    jimpJ
    Firewall > Rules, WAN tab, edit that rule, pick UDP for the protocol, save, apply Update to the latest version, that bug has already been fixed in 2.4.3-p1, released a month ago.
  • OpenVPN + DNS Resolver + FQDN resolution

    2
    0 Votes
    2 Posts
    1k Views
    B
    @mightyschwartz Hi, did you ever find a solution for this? I know this is an old topic but I'm having the same issue... Thanks, B.
  • Linux OpenVPN client registering with DNS

    1
    0 Votes
    1 Posts
    664 Views
    No one has replied
  • Only connecting in User Auth, not SSL/TLS + User Auth......

    2
    1 Votes
    2 Posts
    452 Views
    E
    Figured it out. You have to have a separate "user" cert and a separate "server" cert. Doh!
  • OpenVPN settings and outbound NAT ?

    4
    0 Votes
    4 Posts
    624 Views
    ?
    Ok, I think I get it now, It confused me when the VPN is added it appeared to 'cutoff' the normal traffic from LAN to WAN Dave.
  • Pia port forwarding

    2
    0 Votes
    2 Posts
    614 Views
    M
    Would need more info to offer more targeted troubleshooting help, but a few gotchas that I've seen and learned: Once you assign the tunnel to an interface, make sure you bounce the tunnel afterward If you're running a remote access server, edit the rules on your OpenVPN tab so the source address is explicit to your tunnel network. Otherwise, incoming traffic will match on the wrong interface. In other words, if there's an any/any rule on your OpenVPN tab, either remove it or modify it so the source address is explicit to the other services you are trying to run (e.g. a remote access server or another tunnel) Verify your Outbound NAT mode is in either Hybrid or Manual and that you have NAT mappings NAT'ing egress traffic to the PIA address on the PIA interface. Verify your port forwards are configured on the PIA interface and have a Destination Address of your PIA address Verify the policy routing rule on your LAN tab is configured with the correct source address, has the PIA gateway and is above your LANnet/any (or any/any) rule that would otherwise send the traffic out the default gateway.
  • [Solved] OpenVPN Documentation Sticky

    2
    0 Votes
    2 Posts
    471 Views
    DerelictD
    Fixed. Thanks for pointing it out.
  • Do I need to use Enable NCP - Enable Negotiable Cryptographic Parameters?

    7
    0 Votes
    7 Posts
    3k Views
    DerelictD
    Yes, you are correct.
  • Export OpenVPN server?

    7
    0 Votes
    7 Posts
    1k Views
    K
    While i was testing out the exporting from pfsense 2.2.4 to 2.3.5 i got the certs working just when i connect i keep getting that auth failure, i even copy and pasted the password thinking i was going mad crazy. Pictures: pfSense 2.2.4 [image: 1528744936318-cfff7347-95d8-4806-84cc-308d34a310c8-image-resized.png] [image: 1528745213313-clipboarder.2018.06.11-resized.png] pfSense 2.3.5 [image: 1528745034722-clipboarder.2018.06.11-005-resized.png] [image: 1528745034637-clipboarder.2018.06.11-004-resized.png] [image: 1528745034553-clipboarder.2018.06.11-003-resized.png] Error: [image: 1528745151952-clipboarder.2018.06.11-006.png] Thank you
  • Site to Site overriding my WAN? (SOLVED)

    10
    0 Votes
    10 Posts
    962 Views
    K
    I guess your right, tried on my test enviroment 2 pfSense boxes both running 2.3.5 and the Site 2 was using its own WAN rather then using Site 1 WAN
  • 0 Votes
    14 Posts
    4k Views
    DerelictD
    No. I do not have Rogers. If you packet capture on WAN for port 443, attempt a connection, and it arrives, the ISP isn't filtering it. If it doesn't arrive they are or someone else is.
  • This topic is deleted!

    3
    0 Votes
    3 Posts
    86 Views
    No one has replied
  • 0 Votes
    21 Posts
    6k Views
    T
    @grimm-spector Exactly, it will work just fine :)
  • Password in client export

    7
    0 Votes
    7 Posts
    1k Views
    johnpozJ
    Yeah not a big issue, when you need to install into something that wants to see a password you can just add it via openssl.. Was just curious - thanks. When your wanting your ios phone to connect to a eap-tls wifi network it wants a password. It will not take blank, and space doesn't work, etc. Not a big deal if doing a handful.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.