• Minor issue - Changing WAN IP breaks OpenVPN until restart

    4
    0 Votes
    4 Posts
    986 Views
    M
    @Pippin: There is the –float directive. See manual 2.4: https://community.openvpn.net/openvpn/wiki/Openvpn24ManPage How that is handled by pfSense firewall. i do not know, just try it. As I read about the float directive, it appears to deal with incoming connections from clients and does not address updating the IP that the OpenVPN service is bound to after a WAN IP change on PFsense.    E.g. if a client is on a laptop connected to a flaky cellular hotsot and the connection breaks briefly causing the hotspot to reconnect and acquires a new public IP … the float directive will allow the client to re-connect and authenticate even though subsequent connections (post reconnect) are coming from a different IP than the initial connection.
  • [Solved] How to configure openvpn with ip fixed?

    16
    0 Votes
    16 Posts
    2k Views
    J
    True, every day learning more …
  • Nextcloud Deployment Possible for me? Issues = CGN, etc. (take 2)

    1
    0 Votes
    1 Posts
    382 Views
    No one has replied
  • Openvpn client export utility

    8
    0 Votes
    8 Posts
    3k Views
    johnpozJ
    You do not need to create user in pfsense to allow for vpn access.  You just need to create a user cert using the CA you setup for your openvpn.
  • Design question

    2
    0 Votes
    2 Posts
    504 Views
    M
    :) No opinions at all? Is this soo bad cfg approach that noone won`t even comment it? :)
  • NAT through openvpn tunnel

    19
    0 Votes
    19 Posts
    12k Views
    A
    @Derelict: Then you are still performing NAT there. Turn that off. Would you be able to explain? Thank you
  • OpenVPN server low upload throughput

    6
    0 Votes
    6 Posts
    979 Views
    E
    @johnpoz: I would try the fast i/o option and play with your send/recv buffers while doing your testing  Does that help? It got a little better when enabling fast i/o, It seemed like I got the best speed (~4 Mbit/s) with 2.00 MiB send/receive buffer. I still think I could expect higher speed than this no?
  • NAT through OpenVPN connection

    2
    0 Votes
    2 Posts
    534 Views
    DerelictD
    https://forum.pfsense.org/index.php?topic=135680.msg743942#msg743942
  • [Solved] DHCP clients on LAN do not see OpenVPN network

    5
    0 Votes
    5 Posts
    749 Views
    F
    @marvosa: What is the LAN subnet on both sides? thanks. fixed by defining "Client Specific Overrides" and``` iroute 192.168.1.0 255.255.255.0;
  • [Solved] Access local devices over VPN (Yet Another)

    2
    0 Votes
    2 Posts
    494 Views
    G
    SUCCESS! Looks like it was me all along. I had left the /8 mask on my LAN Network. So really I was running 10.0.0.0 255.0.0.0 I changed my LAN Interface to 10.0.0.0/24, rebooted DHCP devices (or release/renewed) and suddenly I can access all my local devices. OI! It makes sense to me now because my VPN IP pool was technically WITHIN my LAN network. Ever have one of those days? The last 3 were that for me. Oi… Hope this helps someone else!
  • OpenVPN Site to Site Issue

    8
    0 Votes
    8 Posts
    1k Views
    M
    Post the server1.conf from the server and the client1.conf from the client, so we can offer a targeted troubleshooting effort. I see one issue right off the bat: I have set "IPv4 Remote Network(s)" on both client and server to use the same IP network. In a routed solution, all LAN subnets have to be unique and non-overlapping… i.e. the server-side LAN has to be different than the client-side LAN, which should be reflected accordingly in the IPv4 Remote network(s) box on both sides.
  • 0 Votes
    10 Posts
    2k Views
    DerelictD
    In order to do the outbound NAT to effectively use an OpenVPN provider you must create an assigned interface. Rules on the OpenVPN tab will only affect inbound traffic (which should be none in almost all cases) not outbound.
  • Google oath2 and OpenVPN

    4
    0 Votes
    4 Posts
    1k Views
    johnpozJ
    Yeah figured give you the good news ;)  Not that its been on the books for a year… heheeh
  • Force openvpn client to disconnect after x time

    1
    0 Votes
    1 Posts
    365 Views
    No one has replied
  • Question about project 2 pfsense in site-to-site and nat

    1
    0 Votes
    1 Posts
    303 Views
    No one has replied
  • [solved] Can't reach OpenVPN Clients from LAN

    5
    0 Votes
    5 Posts
    2k Views
    P
    The only drawback of this could be that you possibly override other routes on the client with that. Yes, that happened ;D so I had to refine the pushed routes a bit. Now it seems that things are working as intended. I will ponder a bit about NATing the traffic and if it might improve things, but the origin problem is solved. Thank you very much for helping!
  • Routing certain ips through openvpn

    12
    0 Votes
    12 Posts
    3k Views
    T
    think i have worked it out, I set them to assigned instead of static added the static leases in pfsense, and they seem to be applying okay, I have two dns servers set to the static leases, but when i run a leak test four are showing? why does this happen? Thanks again!
  • Site-to-Site VPN with VLANs

    5
    0 Votes
    5 Posts
    3k Views
    L
    Thanks for the answer! I'll give it a shot.
  • No web traffic passing through OpenVPN interface

    8
    0 Votes
    8 Posts
    2k Views
    N
    Hi All, let me give you an update on this. I finally got it resolved last week but just wanted to see how long it's going to last before giving you any update. I deleted all my previous OpenVPN configurations, CA's, client certificates and interfaces, and defaulted firewall NAT Outbound rules and some how I got and assigned the correct vyprvpn interface (I was previously prompted to always assign ovpnc2 interface that is not working properly instead of ovpnc1, and finally I got ovpnc1 interface assigned which might resolved that issue with web traffic). I did start following the guide from the link https://forum.goldenfrog.com/t/opnsense-firewall-openvpn-client-working/3630 (mainly OpenVPN client setup) which help me to get vyprvpn connection to vyprvpn server hk1.vpn.goldenfrog.com up and running but  setting NAT –> Outbound --> to Hybrid and adding a rule manually didn't work for me so I just set NAT --> Outbound --> to Manuall and added new mapping rules based on existing ones, and changed the interface to vyprvpn in my case on all mirrored rules, and then I finally set a Gateway from GW_WAN  to VYPRVPN_VPNV4 in my case in Firewall-Rules-LAN. I'm happy to say that my vyprvpn connection to vyprvpn server has been up and running for more than a week. That test was done in Europe so I'll help my team mate who is located in China to set pfSesne as VyprVPN OpenVPN client at our China's office and test the connection. Hope it will end up ok. If someone needs more info regarding to that case I can provide a screenshots with my full pfSense VyprVPN OpenVPN client and firewall rules configuration. Thank you all for your help once again.
  • 0 Votes
    6 Posts
    2k Views
    Z
    meh, after some further fun trail and error I found the problem. There was an old and disabled IPSec rule in conflicting subnet range. It looks like also it was disabled and definitely offline it still hindered OpenVPN to add its routes. After deleting it completely and another restart site-to-site works. And for further reference: yes, now also the routes to the remote OpenVPN subnets show up in "Diagnostics / Routes".
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.