• How do I configure OpenVPN to wait for high-latency SOCKS proxies?

    2
    0 Votes
    2 Posts
    3k Views
    M

    Op (I, that is) didn't take this OpenVPN FAQ seriously enough:

    One of the most common problems in setting up OpenVPN is that the two OpenVPN daemons on either side of the connection are unable to establish a TCP or UDP connection with each other.

    This is almost [always] a result of:

    A software firewall running on the OpenVPN server machine itself is filtering incoming connections on port 1194 [here 5000-5007]. Be aware that many OSes will block incoming connections by default, unless configured otherwise.

    There's no problem with OpenVPN.

    I just neglected to create a firewall rule for WAN in the pfSense VM that's running the OpenVPN servers, to provide access for the hidden-service proxy in the Tor-gateway pfSense VM.

    How embarrassing. But this question should remain, I think, in case others make the same dumb mistake that I did.

  • Monitor Traffic through OpenVPN

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Viscosity export adding .p12 line but no .p12 file

    11
    0 Votes
    11 Posts
    3k Views
    G

    Yes, in fact it just happened to me again with another VPN profile… Tunnelblick defaults to 2.2, so people that use Tunnelblick by default will have trouble with this until they change the OpenVPN version!

    ![Screen Shot 2013-11-12 at 12.17.32 PM.png](/public/imported_attachments/1/Screen Shot 2013-11-12 at 12.17.32 PM.png)
    ![Screen Shot 2013-11-12 at 12.17.32 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2013-11-12 at 12.17.32 PM.png_thumb)

  • Full access to four public IPs from remote location via OpenVPN

    1
    0 Votes
    1 Posts
    887 Views
    No one has replied
  • OpenVPN Client Export Utility problems with openvpn 2.2 verify-x509-name

    3
    0 Votes
    3 Posts
    8k Views
    M

    as far as i know 1.1.4 and 1.1.5 have the verifiy-x509 removed for only the Yealink phones
    se this thread: http://forum.pfsense.org/index.php/topic,68398.15.html

  • Setup FW rules for multiple OpenVPN interfaces

    4
    0 Votes
    4 Posts
    2k Views
    M

    Thanks for your reply.  I decided to abandon this configuration and instead not user OPTx interfaces for the OpenVPN tunnel interfaces.  Also I realized I don't need NAT between my internal VPNs and LANs.  So even that is simpler the new way.

    I do think that I misconfigured the outbound NATs and somehow that affected the original issue, but I can't say for sure.

    Thanks,
    Miki

  • Using OpenVpn on the LAN interface

    7
    0 Votes
    7 Posts
    4k Views
    G

    The beauty of OpenVPN, is that its an application level solution, so if it helps to visualise it, think of it as you would think of a web server application or a telnet application. In this way, your proposed scenario is perfectly suitable for OpenVPN (and not for other VPN technologies).

    This is unlike the IPSec or PPTP VPNs on your ASA (where I think you might be coming from, from reading your comments) which require specific lower level protocols to work (OSI level 3), and which need direct access to the WAN interface and no playing around with NATs and firewall transversals (it IS possible but its not natural for these VPN technologies).

  • Multiple VPNs

    4
    0 Votes
    4 Posts
    1k Views
    M

    You might be interested in http://en.wikipedia.org/wiki/Cloudvpn.

    It's apparently abandoned, but I played with it a few years ago, and it does work.

  • OpenVPN as client tunnel

    3
    0 Votes
    3 Posts
    1k Views
    I

    Hard to believe I miss the force all traffic check box. Thank you!

  • PfSense OPENVPN Client Cannot Ping to LAN Network

    4
    0 Votes
    4 Posts
    14k Views
    DerelictD

    Firewall rules on the OpenVPN interface determine what traffic is permitted to pass from remote OpenVPN clients/networks through pfSense to other interfaces (like LAN/OPT1.)

    Try a pass any any to LAN subnet on the OpenVPN firewall rules tab to get it working then clamp it down to specific hosts/ports if desired.

  • OpenVPN is not working

    2
    0 Votes
    2 Posts
    1k Views
    DerelictD

    Not even close to enough information provided.

  • Adding static routes for VPN users

    1
    0 Votes
    1 Posts
    793 Views
    No one has replied
  • OpenVPN and radius

    1
    0 Votes
    1 Posts
    970 Views
    No one has replied
  • Error after upgrade to 2.1 in topology

    4
    0 Votes
    4 Posts
    2k Views
    jimpJ

    Is your AD auth happening using RADIUS? It looks like your RADIUS server is passing back an invalid IP to the client, from the output. Or at least one that isn't valid given the server configuration.

  • How many session per a user account openvpn in pfsense ?

    4
    0 Votes
    4 Posts
    3k Views
    P

    Thanks jimp,

  • OpenVPN Bridge on pfsense: once LAN pings clients, connectivity breaks

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • 0 Votes
    3 Posts
    3k Views
    L

    Yep. I did some testing.
    I haven't been able to set up an OpenVpn. Seems the two Firewall has a too different approach on the subject :-)
    Due to my current setup I can't find a common setup. On Endian I'm using Openvpn with PSK and Username/Password credential and seems it's not possible to use them in pfSense.
    I tried also IPSEC but while pfSens has an extended set of options, Endian as a lesser support of it.

    If someone could say "Yes, I did it and it works!", I'd do more tests but i'm not optimist. So far I didn't found evidence that it could be done.

  • 404 Error - Client Export and Shared Key Export

    3
    0 Votes
    3 Posts
    1k Views
    R

    Thanks - that solved the problem

  • Using OpenVPN but not on main LAN (Gotcha)

    1
    0 Votes
    1 Posts
    937 Views
    No one has replied
  • VPN Naming Labels

    6
    0 Votes
    6 Posts
    1k Views
    GruensFroeschliG

    Thanks for the clarification.
    For me the easiest rule to follow is:
    If you have more than one instance, assign all instances and don't use the openvpn tab.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.