• Pinging only one server though VPN

    3
    0 Votes
    3 Posts
    701 Views
    K

    opps thanks I have no clue why it was not showing the rules i rebooted and now it is.

    Thank you :)

  • OpenVPN no lan Ip released

    3
    0 Votes
    3 Posts
    865 Views
    E

    @viragomann:

    Your LAN and WAN are in same subnet. Are they connected to the same virtual network?
    If not maybe the traffic is miss-routed as a result.

    thanks for replying see attached.

    esxi.jpg
    esxi.jpg_thumb

  • OpenVPN no traffic going through it

    6
    0 Votes
    6 Posts
    1k Views
    R

    Worked Thanks!

  • "No server certificate verification method has been enabled"

    2
    0 Votes
    2 Posts
    3k Views
    johnpozJ

    And where are you checking th server?  Why do you have user root in there??

    dev tun persist-tun persist-key cipher BF-CBC auth SHA1 tls-client client resolv-retry infinite remote snipped 443 tcp-client lport 0 verify-x509-name "pfsenseopenvpn" name pkcs12 pfSense-TCP-443-snipped.p12 tls-auth pfSense-TCP-443-snipped-tls.key 1 ns-cert-type server comp-lzo adaptive

    server

    dev ovpns1 verb 1 dev-type tun dev-node /dev/tun1 writepid /var/run/openvpn_server1.pid #user nobody #group nobody script-security 3 daemon keepalive 10 60 ping-timer-rem persist-tun persist-key proto tcp-server cipher BF-CBC auth SHA1 up /usr/local/sbin/ovpn-linkup down /usr/local/sbin/ovpn-linkdown local snipped tls-server server 10.0.8.0 255.255.255.0 client-config-dir /var/etc/openvpn-csc tls-verify "/usr/local/sbin/ovpn_auth_verify tls 'pfsenseopenvpn' 1" lport 443 management /var/etc/openvpn/server1.sock unix max-clients 2 push "route 192.168.1.0 255.255.255.0" push "route 192.168.2.0 255.255.255.0" push "route 192.168.3.0 255.255.255.0" push "dhcp-option DOMAIN local.lan" push "dhcp-option DNS 192.168.1.253" ca /var/etc/openvpn/server1.ca cert /var/etc/openvpn/server1.cert key /var/etc/openvpn/server1.key dh /etc/dh-parameters.2048 tls-auth /var/etc/openvpn/server1.tls-auth 0 comp-lzo adaptive persist-remote-ip float

    servermode.png
    servermode.png_thumb
    clientcheckservercn.png
    clientcheckservercn.png_thumb

  • Open VPN Site to Site LAN bridge *Solved*

    2
    0 Votes
    2 Posts
    1k Views
    J

    Right I have found the issue. They are VMware installed and I didn't realise that promiscuous mode needed to be enable on the interface of the VMware side. You will also need forged transmits on.

  • OpenVPN - No Lan Connectivity

    12
    0 Votes
    12 Posts
    2k Views
    D

    No pushing of gateways is required, that gets handled automatically when the client connects to the OpenVPN server.

    You can watch the process in action.
    Go to the OpenVPN client icon, rgt-click->Edit Config then add the line "Verb 5" to the end of the config file and save it.
    Reconnect the client to the OpenVPN server and "View Log" on the client after it connects.
    You'll have a whole bunch of excess verbage, but near the end you'll see some lines like:

    "C:\Windows\system32\route.exe ADD 192.168.x.x MASK 255.255.255.0 10.x.x.x"

    These lines execute the Windows ROUTE command to tell your client how to send traffic to the OpenVPN server's network.

    What subnets are you now using for:

    pfSense LAN? OpenVPN tunnel? Remote PC's LAN?

    These three items must all be unique networks as we said earlier.

  • Restart / reconnect OpenVPN client

    1
    0 Votes
    1 Posts
    969 Views
    No one has replied
  • Site-to-Site OpenVPN…only access from server, not client

    6
    0 Votes
    6 Posts
    1k Views
    J

    @Derelict:

    Your rule on OpenVPN was TCP only.  Ping is not TCP, it's ICMP.  Many protocols are not TCP.

    Wow.  I must have looked at that rule and compared like 10 times and still missed that.  Yesterday was not my day.  I guess 12 hours of upgrading everything on my entire home network took a toll on me.

    Thanks for that catch.

  • OpenVPN - many users Local Port Question

    3
    0 Votes
    3 Posts
    708 Views
    P

    Thanks so much for the answer. Just what I needed!

  • NAT internet traffic from specific interface through OpenVPN

    2
    0 Votes
    2 Posts
    824 Views
    V

    This is my settings for «normal» openvpn client. LAN -> OpenVPN client -> OpenVPN gateway -> OpenVPN interface.

    Make this a rule, but for OPT1. Maybe this will help you.

  • 0 Votes
    2 Posts
    801 Views
    V

    I made a virtual machine for the test (84,4 МБ).
    Start VirtualBox. File -> Import -> pfSense.ova.
    Start VM pfsense.
    After start go to 192.168.1.10
    Login admin
    Pass pfsense
    Menu VPN -> OpenVPN -> Client.
    The settings in the screenshot.

    An IPv4 protocol was selected, but the selected interface has no IPv4 address.

    How fix this error?

  • Email notify on OpenVPN Connection

    1
    0 Votes
    1 Posts
    610 Views
    No one has replied
  • Open vpn timeouts

    5
    0 Votes
    5 Posts
    1k Views
    D

    disabling gateway monitoring fixed the problem. I guess cable is just variable and not clean.

  • Syslogging over VPN, TCP or UDP?

    1
    0 Votes
    1 Posts
    546 Views
    No one has replied
  • ExpressVPN

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • External OpenVPN client can't see LAN devices

    17
    0 Votes
    17 Posts
    5k Views
    H

    Thank you dr41 and doktornotor forgot to do that. That at least resolves the error in the OpenVPN status window

    However For some reason it still is an unidentified network with no internet or my "home" network access. I have a bridge in my pfsense config so I was wondering if the vpn server needs to be in the bridge as an enabled device.

  • OpenVPN + LDAP - Password expire in remote

    2
    0 Votes
    2 Posts
    619 Views
    D

    No such thing there.

  • Openvpn working with auth only not SSL/TLS

    2
    0 Votes
    2 Posts
    659 Views
    P

    I have just used a road-warrior connection with SSL/TLS+User Auth to both a 2.1.5 and a 2.2.2 system. So it does work. I am using OpenVPN Manager on Windows 7 and config produced by the OpenVPN Client Export package. For me, it "just works".

    TLS key negotiation failed to occur within 60 seconds (check your network connectivity)

    That message usually means the client is simply not reaching the server - FQDN used by the client does not resolve to the proper server IP, server is not listening on the port…
    Post your server settings, what client you are using, how you installed on the client.

  • How to interpret firewall log

    2
    0 Votes
    2 Posts
    928 Views
    johnpozJ

    What interface are those rules on?  And can we see the full set of rules.  And screenshot of your firewall log vs that text would be much easier to read.

  • [Solved] Split Tunnel

    10
    0 Votes
    10 Posts
    2k Views
    DerelictD

    Hmm.  Works fine for me.  What are you exporting to?

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.