• OpenVPN speed vs hardware

    10
    0 Votes
    10 Posts
    4k Views
    R
    @Rango: @Ryu945: Crypto-Dev by itself also did nothing.  I only got it to work when both were turned on. That's interesting. I now only have Crypto Dev on both sides and it boosts 20% so i can get 120Mbs on N3150 and medium is about 115-117Mbps but when i switch to only AES-NI it goes down by 20% to base line with is about 100Mbps which is what you see in screenshot above. I tried it every possible combination and that's what i'm getting. At least i'm happy Cryptodev is working and boosting a bit, 20%. Maybe if AES-NI would work it would boost much more. I dunno what the expectation of hardware based acceleration should be. I just reported what my testing yielded. I am happy with pfsense but it seems AES-NI module is not working and looks like Cryptop Dev is FreeBSD solution to it, for now maybe. Maybe in 2.5 this will change when they focus on it.  I can't wait if so. I am however disappointed i purchased N3150 however. I didn't do enough research then. The fact that i owned asus 87u also purchased for encryption. It is now exclusively AP. I guess as they say u learn on your own mistakes. I've learned. Thanks for posting your results. :) I did this AES-NI test with the version that came out before the Spectrum/Meltdown bug so I don't know if things have changed in the version I currently run.  I will have to run more test at a later time.  I did notice a massive speed reduction after that update.
  • Multiple VPN and Multiple Wan

    3
    0 Votes
    3 Posts
    705 Views
    R
    1)  Do you have duel WAN working by itself? 2)  Just for a sanity check, is there a reason your using two WANs?
  • PfSense 2.4.2P1 - OpenVPN with CARP VIP

    3
    0 Votes
    3 Posts
    621 Views
    R
    Thanks for the assist.  Turns out, I had to generate a new VPN profile for my client to get it working.  Editing the old VPN config (changing port numbers and IPs) did not work…
  • [Solved] Cannot access LAN when bypassing VPN

    7
    0 Votes
    7 Posts
    861 Views
    T
    @Derelict: It works if it is positioned ABOVE the policy-routing rule in the interface rule set. Forgive me, I guess I mix up the terms… Please see attached screenshot, that is what I thought you meant by putting it on the WLAN interface. But now I made a new floating rule like the 2nd screenshot and it works, I guess that is what you meant is a more neat solution? ![WLAN rules.PNG](/public/imported_attachments/1/WLAN rules.PNG) ![WLAN rules.PNG_thumb](/public/imported_attachments/1/WLAN rules.PNG_thumb) [image: Finale.PNG] [image: Finale.PNG_thumb]
  • OpenVPN Site to Site Routing

    3
    0 Votes
    3 Posts
    708 Views
    DerelictD
    One of the nice things about OpenVPN is that clients can be behind other routers with generally no problems. If the tunnel is coming up and the site2 pfSense has a route for 192.168.190.0/24 into the ovpncX interface, then that is configured correctly. If that is the case I would check the firewall rules for OpenVPN at main to be sure they pass the traffic. If they do I would check the firewalls on the main hosts themselves to be sure they are not blocking the traffic.
  • PIA VPN failing every hour

    3
    0 Votes
    3 Posts
    805 Views
    B
    What server are you connecting to? Have you tried another server with the same results? also given the errors in your logs you have not followed/ matched the OVPN files.    match those as close as possible
  • Restrict PIA openvpn access to only ONE IP on my network…

    1
    1 Votes
    1 Posts
    974 Views
    No one has replied
  • Multi OVPN Clients - Clashing Same Virtual IP Address

    3
    0 Votes
    3 Posts
    632 Views
    H
    Thanks for the response. I know I have set this up in the past with the ip being pushed from the server to the client, but starting to question myself also if it can be done client side. I dont see why not, I dont pull routes from the VPN provider. I did manage to assign static ip client side using the client specific overrides. This was based on assigning static ip per certificate authority. Unfortunately, all the VPN clients share the same certificate authority though - so although I have proven you can assign static ip client side I still havent managed to do it per client. It seems that the ifconfig-push directive works in the 'Client Specific Overrides' section but not in the 'Client' section. ' I dont understand why in the 'Client' section you cannot just specify the ip in 'IPv4 Tunnel Network'
  • VPN client setup advise

    8
    0 Votes
    8 Posts
    1k Views
    RangoR
    @gschmidt: Hi, I bought a 4xNic aes-ni mini pc with pfsense  to replace my home router. The main reason i want to replace my home router is to setup an openvpn client ( Expressvpn). Is it possible to select the ip's which will be using the VPN tunnel? Or is it only possible to exclude the ones not using the VPN tunnel? Greetzzz, Gerben Expressvpn will leak your DNS. You can not setup pfsense with their dns servers. I inquired with them. You will have to point to 3rd party open dns server which will cause you leak dns out.
  • Conel 4g router OpenVPN client to PFsense openvpn server

    2
    0 Votes
    2 Posts
    519 Views
    F
    Well i have the vpn link up now. However i can only ping one way, from the conel 4g router i can see all my devices on the pfsense network. I can ping the virtual ip of 192.168.99.2 and access this via web interface to reach the conel router home page.  I cant however reach any of the devices on the local lan of the conel (192.168.1.xxx). Is there something i'm missing in terms of routing etc?# Thanks
  • How to kill user's OpenVPN connection

    2
    0 Votes
    2 Posts
    359 Views
    PippinP
    See here: https://forum.pfsense.org/index.php?topic=139073.msg776861#msg776861
  • Open VPN Error

    4
    0 Votes
    4 Posts
    705 Views
    johnpozJ
    Entered what data? So your using a tls authentication mode - so the user needs also ta.key, etc. So your client would need 3 the CA, the User and the ta.key…  You imported those all into your nas?
  • Split Routing

    2
    0 Votes
    2 Posts
    581 Views
    H
    https://doc.pfsense.org/index.php/Multi-WAN
  • OpenVPN bridged with LAN VLAN issues

    2
    0 Votes
    2 Posts
    706 Views
    brunovicB
    So after doing some research I have realized that I do not need to assign a bridge to an interface with an IP. I can simply just bridge VPN and LAN with the LAN interface having the IP address. Once I've made those changes everything on the LAN works perfectly fine however I can no longer ping the LAN IP from the OpenVPN client. [image: illustration11.png] [image: illustration11.png_thumb] [image: illustration12.png] [image: illustration12.png_thumb]
  • OpenVPN Connected / LAN Gateway Reachable / LAN Clients not so much

    3
    0 Votes
    3 Posts
    545 Views
    C
    Awesome. I could ping the server from the internal LAN, so I didn't think much about the Windows firewall. After turning that Windows firewall off to test, I could access the server over the VPN just fine. I turned the firewall back on and added a rule allowing incoming traffic from my OpenVPN IP range. We're all good now. Thanks for the help!
  • Unable to connect to OpenVPN from within the LAN

    3
    0 Votes
    3 Posts
    551 Views
    DerelictD
    It's a VPN. Connect from the outside. When you connect from the inside from an address that is in the subnet that is supposed to be routed over the VPN it is not going to work.
  • Netgate SG-1000 to use as OpenVPN client for small side with 20 devices

    1
    0 Votes
    1 Posts
    281 Views
    No one has replied
  • Openvpn + freeradius - unable to log in into VPN

    9
    0 Votes
    9 Posts
    3k Views
    jimpJ
    @Censor: @mislav: I'll try to completely remove all users, certs, freeradius and then try to install it from scratch. I will update you with VPN results. Thanks for now. Hi, to remove the freeradius package and any other dependant package which are no longer needed you have to use this command "sudo apt-get remove –auto-remove freeradius" pfSense is not based on Linux and does not use apt. It uses FreeBSD and pkg.
  • Speed issues using PIA and OpenVPN

    7
    0 Votes
    7 Posts
    1k Views
    B
    @cobrahead: @bcruze: Have you tried enabling aes-ni? I have not. You? yes mine is enabled and being utilized.
  • OpenVPN killswitch

    20
    0 Votes
    20 Posts
    3k Views
    DerelictD
    I would: Set the VPN hosts I want to route only over the VPN to use free, outside name servers (google, quad-9, level3, etc) using DHCP or Static or whatever. Policy route the DNS queries out the VPN with all the other internet traffic. And you're done. Everything you just described is fine until the VPN is down and all of your DNS breaks for everything.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.