• OPENVPN Client : unable to resolve dns name when trying to reconnect

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    N
    Hi, thanks for your feedback. Please post your results (in a few days).
  • [solved] OpenVPN connects but I can't talk to LAN subnet

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    M
    np, once in a while i share the same boat
  • OpenVPN TAP and Tunnel Network problem

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    F
    Anyone, any idea how to remove "server 0.0.0.0" parameter? I delete it from /var/etc/openvpn/server1.conf but it always come back after system restart. Where I can disable "server" parameter. I need only "mode server" parameter.
  • Cant communicate with slave/backup pfsense instance via OpenVPN

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ
    well the easiest thing to do would be outbound NAT on the LAN interface, source of the openvpn subnet, translated to the LAN IP of the box. Yes, you'd have to switch to manual. You could do 1:1 NAT on LAN from an OpenVPN IP to a VIP (non-CARP!) in the LAN subnet, but that would only work for one client with a static IP.
  • Why doesn't VPN connection re-initiate when dropped?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Site to site routing bug

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H
    check if the routing is correct on both ends … it can happen that one side is able to send traffic, but that the other side does not know how/where to return the replies
  • Site to Site Can ping from one side but not the other

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    E
    I've had similar issues like this in the past. Some things to look at: as heper said, check your routing table. make sure there is a route in  site A's table that routes traffic to siteB_subnet via the openvpn interface (do the same check for site B) make sure you have the allow rules on the openvpn tab check your lan rules on A, see which rule get hits when your sending traffic from A to B and double check that its using the "default" gateway. if there is no such rule, add one that has source->lan_subnet dest-> siteb_subnet gateway->default Run a wireshark on the receiving end (the machine on site B that you're pinging), see if the ping requests are coming in (could be that the responses aren't going from B to A properly) -E
  • Forwarding OpenVPN server ?

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • OpenVPN Performance, specifically number of connections

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • OpenVPN User Auth + Static key security?

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Set Static Internal IP for OpenVPN Clients

    Locked
    7
    0 Votes
    7 Posts
    9k Views
    I
    @jimp: coughcoughcough :-) OOOOHHH, I was looking in pfSense's FAQ in the OpenVPN sections…  :D Thanks for the link!
  • Possible to have clients recieve address from internal lan subnet

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    Cry HavokC
    There is no tunnel network - when using TAP the client is effectively directly connected to the LAN. It gets a DHCP lease from the LAN DHCP server. I would recommend you read the OpenVPN documentation so you understand the basics of what you're dealing with.
  • Pfsense open vpn client site to site

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    Cry HavokC
    If it is just OpenVPN under the hood of Zerina, then yes. The sticky post at the top of this forum for site to site covers the process, the GUI on Smoothwall should be the only difference.
  • Single Client Package, Multiple Users

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    I
    Currently we have a bunch of 'satellite' systems that all serve the same purpose and don't have active users. It was looking to be a bit tedious (as we are constantly sending out new systems and such) to have to create a separate user in pfSense for our fluid usage of the network. However, as you have mentioned, if the certificate is compromised then anyone could have access to the network (which only allows access to one IP but that is beside the point) and we'd have to replace the certificate on all the systems. Is there an easier way to create a user/certificate combination without having to go through so many steps every time? On IPCop, for example, you type in the hostname and one or two other things and it created the user and certificate and everything.
  • OpenVPN - 2 clients with different access rules

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    That is in Client-Specific Overrides in the OpenVPN config. Make an entry for each user's certificate CN, give each of them a hardcoded tunnel network (a /30 inside of your larger tunnel network on the vpn), then set your firewall rules accordingly.
  • OpenVPN Site-to-Site dropped and only comes back after reboot

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C
    I set both the server and client to "any" and it still doesn't come back up until it gets rebooted. For example, the client machine was down for the weekend.  When I powered it back up the VPN would not come back up until I rebooted the server.
  • OpenVPN connection on unmapped port, UNDEF user, persistent respawning?

    Locked
    5
    0 Votes
    5 Posts
    9k Views
    jimpJ
    You may be seeing the clients randomized source port, not the server's listening port.
  • OpenVPN Status Page Error

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    Edit the advanced options of each OpenVPN instance and remove any "management xxx xxxx;" declarations you have there. It's handled differently in 2.0.
  • TLS Error: TLS key negotiation failed to occur within

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    Yes, it works fine. That error generally means that the openvpn traffic is not making it through the firewall. Make sure you are allowing the traffic into the OpenVPN port on the server.
  • OpenVPN <=> Yealink T26 IP Phone

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.