• [Solved] AUTH_FAILED using Active Directory as backend for OpenVPN

    9
    0 Votes
    9 Posts
    5k Views
    V
    @doktornotor: @viandham: The problem was the binding account. For some reason, it accepts "<accountname>" on server, but needed to be "accountname@domain.tld" on this one. When I entered that, it worked. No idea why./accountname@domain.tld</accountname> Hmmm… In AD environment, it must be either DOMAINNAME\Username or Username@DOMAINNAME. "For some reason" it could have never worked unless used properly. Thats not true under all circumstances, I would argue.. I just rechecked, and I have 4 LDAP backends setup in my Servers-tab on the "working server", and all of them work. In fact, I'm connected via one of them right now. And neither of them have any domain specified in the binding credentials. All backends are AD. The domain is, however, specified in the search scope, Base DN. But that's probably not used until the binding is complete, and the actual user is authenticated. If there is only one domain configured (no multi-domain forrests etc), maybe it assumes that domain? At least these are working for me, and have been for years :)
  • Local connection ok, remote not

    2
    0 Votes
    2 Posts
    681 Views
    P
    Figured it out. I needed to add a static route to my router so the VPN packets would reach the pfsense machine rather then bounce harmlessly off the gateway.
  • Safe to have PKI CA on same box as OpenVPN?

    3
    0 Votes
    3 Posts
    872 Views
    C
    Sounds reasonable. I am only using the pfSense hosted CA for the VPN.
  • Cannot locate the source of this error: "no IP address found for anyto"

    9
    0 Votes
    9 Posts
    3k Views
    E
    Thanks Chris, i'll do some more testing and let you know if i find something else. A last question. Should the AVPair imported rules be seen in the firewall configuration panel or somewhere else? Thanks Pablo
  • Route openvpn clients through site-to-site vpn

    7
    0 Votes
    7 Posts
    1k Views
    M
    I have posted a thread but no answers as of yet. just saw this and thought maybe this is the issue im having
  • All traffic from LAN to OpenVPN client

    4
    0 Votes
    4 Posts
    1k Views
    H
    Post screenshots of all related GUI pages. Are you sure the tunnel is working?
  • Pregenerated Diffie-Hellman parameters

    3
    0 Votes
    3 Posts
    1k Views
    C
    Awesome! Is /etc/dh-parameters.* unique per pfsense installation or is it the same for all installations?
  • [solved] Problems with OpenVPN service and Webfrontend

    3
    0 Votes
    3 Posts
    976 Views
    R
    Did a clean reinstall and seems to be fixed. I think topic can be closed
  • DNS Resolver service will not stay running if OpenSSL VPN client enabled

    1
    0 Votes
    1 Posts
    660 Views
    No one has replied
  • Enable authentication of TLS packets

    2
    0 Votes
    2 Posts
    1k Views
    C
    I think I found the answer here: https://openvpn.net/index.php/open-source/documentation/security-overview.html One notable security improvement that OpenVPN provides over vanilla TLS is that it gives the user the opportunity to use a pre-shared passphrase (or static key) in conjunction with the –tls-auth directive to generate an HMAC key to authenticate the packets that are themselves part of the TLS handshake sequence. This protects against buffer overflows in the OpenSSL TLS implementation, because an attacker cannot even initiate a TLS handshake without being able to generate packets with the currect HMAC signature.
  • OPENVPN with OSPF and REMOTE configured for redundancy.

    4
    0 Votes
    4 Posts
    1k Views
    S
    Anyone? :(
  • OpenVPN TAP not working

    2
    0 Votes
    2 Posts
    981 Views
    D
    My car suddenly won't go… help please!!!  ::) Dude, post some logs and configuration, or try a crystal ball.
  • Connect to OpenVPN Access Server?

    46
    0 Votes
    46 Posts
    21k Views
    D
    I just noticed 2 new lines in SysLog (OpenVPN) Nov 11 21:26:33 openvpn[22448]: Authenticate/Decrypt packet error: bad packet ID (may be a replay): [ #1131750 ] – see the man page entry for --no-replay and --replay-window for more info or silence this warning with --mute-replay-warnings Nov 11 22:15:56 openvpn[22448]: Authenticate/Decrypt packet error: bad packet ID (may be a replay): [ #85096 ] – see the man page entry for --no-replay and --replay-window for more info or silence this warning with --mute-replay-warnings above these 2 lines, everything is still the same as in the image above this post. Anything i should worry about? Thanks
  • OpenVPN Connect with intermediate CA

    1
    0 Votes
    1 Posts
    637 Views
    No one has replied
  • Passing client routes via Active Directory

    14
    0 Votes
    14 Posts
    3k Views
    O
    I would like to thanks everyone for the help I was able to get working exactly what I wanted by having radius push routes and firewall rules all managed from AD. Thanks Again
  • Delay related performance issues with OpenVPN

    3
    0 Votes
    3 Posts
    2k Views
    B
    do you use outbound-NAT ? do you have more than one openVPN-Server running on that pfsense? if yes, look here: https://forum.pfsense.org/index.php?topic=101115.0
  • Is there any way at all to get Private Internet Access with AES 256?

    7
    0 Votes
    7 Posts
    2k Views
    L
    how do I do the edited client config cipher AES-256-CBC auth SHA256 thing? Thanks
  • OpenVPN "Unable to contact deamon"

    1
    0 Votes
    1 Posts
    605 Views
    No one has replied
  • OpenVPN no longer connects from iOS Devices following upgrade to 2.1.5

    4
    0 Votes
    4 Posts
    2k Views
    D
    Why'd you be "upgrading" to completely obsolete release now? Yup, +1 on that. From all accounts 2.2.5 is stable, especially as far as OpenVPN. I've got more than a few iOS devices talking to  various 2.2.5 sites using OPenVPN. I'd be inclined to make sure your pfSense is up to date, then make sure the iOS client is as well.
  • Updated pfsense and android devices won't connect

    6
    0 Votes
    6 Posts
    2k Views
    johnpozJ
    How many users do you have?? Dude really it takes all of 15 seconds to create a new ca..  Not sure where the problem is here with redoing your setup.. Delete your openvpn setup and run through the wizard it takes all of really to be honest if it takes you more than 3 minutes your doing something wrong!!!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.