• Pfsense 2.0.3 OpenVPN bridge TAP

    15
    0 Votes
    15 Posts
    11k Views
    jimpJ

    pfSsh.php playback gitsync RELENG_2_0
    reinstall package
    profit even more (since fixes after 2.0.3 shipped are included in the gitsync)

  • Redirect inbound connections to OpenVPN server to OpenVPN client

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Post-auth Script

    2
    0 Votes
    2 Posts
    2k Views
    J

    I don't have your answer, but I did notice that the page linked is for openvpn access server,  which iirc is the commercial offering and is not the open source package that is used in pfsense and other linux distros.

    So the first thing you will want to determine is if your feature is also available in the open source edition.  Sorry for the non answer but since nobody else had replied maybe you will find this helpful.

  • Can not get connection

    3
    0 Votes
    3 Posts
    1k Views
    S

    Thanks for the reply, where can i find it?

  • OpenVPN to HideMyAss ::RESOLVED::

    8
    0 Votes
    8 Posts
    8k Views
    D

    Resolved the issue by saving the file in /etc/ and as file type .txt.

  • FreeRADIUS + OpenVPN + pfSense for multiple locations/instances

    3
    0 Votes
    3 Posts
    3k Views
    M

    That's exactly the help I needed, thanks so much Jeff!!!

  • Client - pfSense - pfSense

    4
    1 Votes
    4 Posts
    1k Views
    Y

    @phil.davis:

    You are having a "road warrior" server at Site A to "dial-in", then a site-to-site link from an OpenVPN client at site A to an OpenVPN server at site B.
    The tunnel network for "road warrior" and "site-to-site" have to be different subnets - what is in the original post is fine. (I think marvosa has misread your post, as I did when I first looked at it quickly)
    The local network at site A and site B have to be different and not overlapping. e.g. 10.0.0.0/16 and 10.1.0.0/16
    Then it is all standard stuff, no real challenge for pfSense. Put the appropriate things in local and remote network fields of the VPN settings, allow stuff in firewall rules, go.

    All right, it mean that i`m on the right way to apply this. i will give it another try and may also check the firewall settings - the problem could be there..
    many Thanks!

  • To assign an interface for an openvpn connection or not?

    5
    0 Votes
    5 Posts
    3k Views
    S

    @phil.davis:

    For site-to-site links connecting private subnets at multiple locations, and servers for road-warriors connecting in, then you don't need an interface assigned. You can do it all with ordinary OpenVPN config - putting private subnets in the appropriate "local network" and "remote network" fields of the GUI, adding client-specific overrides for site-to-site with multiple clients from remote sites connecting in to 1 server… The GUI fields result in the necessary routes being created, then you use the general OpenVPN tab to allow traffic - often you only want/need to allow traffic between your various private IP subnets.

    As doktornoktor says, if you are OpenVPNing out to a server somewhere for general internet access, then you probably need to add a gateway on the link, and direct certain (or all) public internet traffic over the link... and that needs the interface assigned.

    If you are providing roadwarrior access with openvpn, you could use squid and squidguard to speed up your connections, so in this case you need the interface also assigned.

  • Trying to setup pfsense as client to PIA VPN service…..need help

    4
    0 Votes
    4 Posts
    2k Views
    V

    I was having the same issue and opened a ticket with PIA on it.  I was basing my config off what was provided in the client support site and their instructuctions for pfsense https://www.privateinternetaccess.com/pages/client-support/#pfsense_openvpn and the openvpn config files.  What I learned was to ignore their instructions – i told them they should update them after we realized they were wrong.

    ===

    The first major issue I notice is that we don't use TLS auth, and LZO compression appears to be disabled, could you go ahead and correct these two things and try again? You should also only need to Auth-User-Pass line, everything else under advanced can be removed, as it's handled purely in the main configuration window.

    Thank you,
    Alexander B

    Tier II Technical Support/CSM

    Private Internet Access™
    https://www.privateinternetaccess.com/

    =======

    Attached is a copy of my config that is working.

    config.txt

  • Help with blocking Rule!

    10
    0 Votes
    10 Posts
    2k Views
    D

    Well, if you cannot reboot, then wait.

  • Lan access to OpenVPN

    16
    0 Votes
    16 Posts
    4k Views
    K

    Leave it on TCP unless you travel far far away - hundreds of miles or more.
    After that, switch over to UDP.
    Pretty much all devices will allow multiple configurations and are easily selectable via GUI in the clients.
    So, just run 2 instances of openvpn on your server.
    This is good idea for anyone really - Just to guarantee access with multiple accessible ports/protocols.

  • How to extract the Certificate data??

    5
    0 Votes
    5 Posts
    1k Views
    K

    I'll add it to my PortableApps thumbdrive I keep handy for when I'm forced to go slumming on a windows machine  :)

    Its in their repo - I added it.

  • Open VPN Tunnel Up - Cannot Pass Traffic

    6
    0 Votes
    6 Posts
    3k Views
    M

    Post your server1.conf and client1.conf.

  • OpenVPN Conection Failing *Fixed

    1
    0 Votes
    1 Posts
    4k Views
    No one has replied
  • OpenVPN not coming up on CARP IP

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • PfSense as OpenVPN client - no traffic through tunnel

    10
    0 Votes
    10 Posts
    8k Views
    M

    Just out of curiosity, what kind of device is on the server-side?

  • OpenVPN - No Internet access on Client

    2
    0 Votes
    2 Posts
    2k Views
    M

    Ok, so PFsense on both sides?  Lets take a look at your config…post your server1.conf and client1.conf.

  • Openvpn server not starting (road warrior configuration)

    23
    0 Votes
    23 Posts
    9k Views
    J

    Thanks for the advice!

    I have to wait until after hours to make changes but hopefully will get to it tonight.

    -j

  • PfSense to OpenVPN server - nowhere to specify a server cert

    14
    0 Votes
    14 Posts
    3k Views
    I

    No. The pfSense box is the client (I already have it running just fine as a server using the method you describe).

    I have imported the external CA certs and client cert etc but the tunnel won't establish. I'll pull some logs together and post here.

  • Poor performance and Errors

    5
    0 Votes
    5 Posts
    1k Views
    S

    @GruensFroeschli:

    How are you testing this?
    If you test by downloading from a windows share, then this does in no way reflect the speed the tunnel is capable of.

    Are you using TCP or UDP as transport protocol?
    In general you will have better performance when using UDP.

    Yeah that what I was thinking. Windows share shows about 600k/s and when I look at the WAN interface charts I do see it uploading at all 5Mb/s. I use UDP.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.