• PFSense push LAN routes as OpenVPN Client

    4
    0 Votes
    4 Posts
    2k Views
    M

    Much like cmb already mentioned, why wouldn't you just define your routes on the server side?

  • Protecting private keys on OpenVPN server using a TPM?

    16
    0 Votes
    16 Posts
    9k Views
    johnpozJ

    "is pretty much standard for things like bank inter branch vpn's, hospitals, data-centers etc."

    No No its not… We have a fairly large hospital as one of our customers that I support.  No they do not have any sort of TPM storing the vpn keys be it the remote users coming in, nor to any of the vpn connections between their branches and the datacenter or between each other.

    We also have multiple DCs across the country and the globe, I can tell you that no there is not any TPM storing any of the server keys.  And to be honest I am not aware of any customer even doing it for their remote users, etc..

  • Routing single computer to vpn network

    14
    0 Votes
    14 Posts
    4k Views
    J

    Thanks! work like a charm I did the NAT solution but will maybe to the other one later on.

  • IOS Client timeout - Tunnelblick working

    4
    0 Votes
    4 Posts
    1k Views
    T

    Anyone?

    :(

  • 0 Votes
    4 Posts
    962 Views
    C

    If you don't know what captive portal is, then you probably don't have it enabled. But check Services>Captive Portal. That would intercept web requests. If that's not enabled, what output do you get on the FreeBSD machine for "host pkg.freebsd.org"?

  • Forwarding CIFS/SMB from OpenVPN Client

    3
    0 Votes
    3 Posts
    1k Views
    johnpozJ

    While sure that would be possible, I see that service also provides webdav via ssl, wouldn't that be an easier solution?  And faster?  SMB performance over wan with latency is normally horrific..

  • Setup OpenVPN Remote Access [Close]

    3
    0 Votes
    3 Posts
    1k Views
    H

    Omaigad.. Thank You Very Much. I understand a bit now. ;D ;D ;D

  • OpenVPN status UP, but can not ping

    13
    0 Votes
    13 Posts
    3k Views
    V

    The NTP service will not relate to this issue.

    Let's go to troubleshooting. Take a packet capture (Diagnostic menu > Packet Capture). At server and client select LAN interface and at Protocol ICMP and hit start below. Then start the ping.
    If you see nothing at on site, select OpenVPN interface and repeat it.
    Post the output.

  • [SOLVED] vpn client failing to validate server certificate

    8
    1 Votes
    8 Posts
    15k Views
    D

    I understand that it will get blown away and that manually editing it was the wrong thing to do but I was missing something in the GUI that meant I couldn't get it to work. This, and software upgrades are the only changes I've made in the last year and as I've now got a copy of the working files, after the next upgrade, if things do break, I can put them back.

    I tried putting a chained cert in the CA cert and it didn't work, does the order of the certificates in the file matter? It may also be that the restart didn't work correctly or it needed a reboot after the change to make things work.

    I'm not blaming pfSense here, I'm sure it was probably something I messed up in replacing the certificate. If I get chance I'll try again with a chained cert as the CA and update with the results.

  • Certificate import error?

    7
    0 Votes
    7 Posts
    2k Views
    C

    You'd have to mess with base64. Could you send me a copy of the certificate file? No need for the key portion, and the cert on its own isn't usable for anything.

  • WAN/DHCP affects OpenVPN and gets it out of sync in the web gui

    3
    0 Votes
    3 Posts
    1k Views
    H

    @cmb:

    With it bound to 443, do you have your GUI bound to something other than 443? That might be one reason.

    I'm guessing though it's the issue where OpenVPN writes out the wrong PID in its PID file. What's in your /var/etc/openvpn/serverX.pid file and what is the actual PID of OpenVPN instance that's running? where serverX probably == server1, but could be some other number depending on how many you have and have had in the past.

    I switched the webgui port to 1234 before I created the OpenVPN service. It works fine now since I rebooted it and was quickly able to get back an IP from DHCP.

    It's weird how it got into that state… The openvpn daemon was definitely running (even though it was reported stopped) and I was able to vpn in from the internet once I got an IP.

    The pid file explanation makes sense. I'll try it again in a few days so I can get it in that state again and report back. Thanks for your insight.

  • OpenVPN: How to not allow WAN traffic?

    6
    0 Votes
    6 Posts
    2k Views
    M

    You essentially have two options:

    Configure a client specific override for that one user and each future user with the same situation

    Configure a 2nd OpenVPN server… one full tunnel and one split tunnel.  Then just export the split tunnel package when needed

    From a management overhead standpoint, I think option#2 makes more sense.  This is also the solution that I've implemented.

  • Does openVPN client support updating the resolv.conf ?

    4
    0 Votes
    4 Posts
    1k Views
    C

    Very rarely desirable to do that when the firewall's a client is why it's sat there forever with no movement. It's not hard to add to ovpn-linkup if you want to do so.

  • Openvpn performance issue

    2
    0 Votes
    2 Posts
    860 Views
    H

    just run a speedtest though it with iperf

  • 0 Votes
    18 Posts
    4k Views
    johnpozJ

    So your going to have multiple machines on gce?  An they are going to use this vpn machine as their gateway to your network?  Can you setup the GCE networking that way for their instances?

  • Bridging Multiple VLANS with OpenVPN Tap

    3
    0 Votes
    3 Posts
    918 Views
    A

    I want something like this https://forum.pfsense.org/index.php?topic=66796.0 but there is no answer there too

  • Alternative OpenVPN client

    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    Viscosity is great, we recommend it all the time. The only downside is the cost. If you're OK with the cost it's an excellent bit of software and works on both Mac and Windows without any problems we're aware of.

  • Can ping eveything but remote network

    7
    0 Votes
    7 Posts
    1k Views
    D

    Glad you got it figured out.

    Don't be stranger to the forums (even it's only to eavesdrop) a lot to be learned around here.  ;)

  • Route to external address for VPN users

    3
    0 Votes
    3 Posts
    839 Views
    D

    The other issue you may run into:

    You may need to tell SQL to allow database connections from the OpenVPN subnet.

    I take it access to other devices/applications across the OpenVPN works, it's just a problem with SQL?

  • Differences in nearly identical remote access openvpn's why?

    1
    0 Votes
    1 Posts
    580 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.