• VPN override remote host ip if local network has the same ip

    3
    0 Votes
    3 Posts
    360 Views
    Y

    @Pippin said in VPN override remote host ip if local network has the same ip:

    @yeahmagnets said in VPN override remote host ip if local network has the same ip:

    My remote network is 192.168.1.0/24 and the home network is 192.168.1.24/0

    Change at least the home network:
    https://community.openvpn.net/openvpn/wiki/AvoidRoutingConflicts

    Yeah that is an option but just think that you went to holiday and hotel's network is also 192.168.1.0/24 and some other guest's computer assigned 192.168.1.50 so you can't say leave that ip it conflicts with my file server can you?

    There must be solution.

  • tunnel is up but cannot route traffic from client to remote client

    5
    0 Votes
    5 Posts
    533 Views
    Z

    @viragomann you rock man! I thank you to pointing me to the solution! it's working as expected now!

    ciao!

  • OpenVPN Issue - Multiple Interfaces Not Functioning Simultaneously

    9
    0 Votes
    9 Posts
    703 Views
    N

    @viragomann
    These public ip addresses are my vps where openvpn is installed.

    Yes.

    Yes.

    752fda1f-875d-4f38-8e28-bf917811b24e-obraz.png

  • OpenVPN client export private key password

    6
    0 Votes
    6 Posts
    10k Views
    J

    @wolfsden3

    Download the Most Clients config 1 single file with that it should work

    4a9f6bf1-87fb-41ad-bc29-5108d59fb25b-image.png

  • 0 Votes
    15 Posts
    12k Views
    PippinP

    @Gertjan said in Solved: ExpressVPN connection error Data channel cipher negotiation failed (no shared cipher):

    Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bit RSA, signature: RSA-SHA256

    That's the control channel ;)
    .
    Data channel is this one:

    2023-06-26 11:08:24 us=684115 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key 2023-06-26 11:08:24 us=684160 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
  • OpenVPN cert expiring, need to renew, and server migration

    8
    0 Votes
    8 Posts
    978 Views
    V

    @ipguy
    For further investigation you have to provide the clients and server logs.

    You can try to disable "Data Encryption Negotiation" on the server. If the client has an old config he might not support this feature.

  • Openvpn interface and softflowd

    1
    0 Votes
    1 Posts
    257 Views
    No one has replied
  • I want to pass or not pass VPN by site.

    3
    0 Votes
    3 Posts
    366 Views
    Yet_learningPFSenseY

    @viragomann Thank you very much. While trying various things, I found that by setting the alias and placing it above the VPN configuration in Firewall -> Rule -> LAN, I can bypass specific sites and not route them through the VPN. Thank you for your guidance and help.

  • openvpn over stunnel

    4
    0 Votes
    4 Posts
    772 Views
    H

    @pst thanks, I looked. But I get the same logs
    Jun 20 20:01:24 openvpn 23836 TLS Warning: no data channel send key available: [key#0 state=S_PRE_START id=0 sid=00000000 00000000] [key#1 state=S_UNDEF id=0 sid=00000000 00000000] [ key#2 state=S_UNDEF id=0 sid=00000000 00000000]
    Jun 20 20:01:24 openvpn 23836 TUN READ [29]
    Jun 20 20:01:24 openvpn 23836 TLS Warning: no data channel send key available: [key#0 state=S_PRE_START id=0 sid=00000000 00000000] [key#1 state=S_UNDEF id=0 sid=00000000 00000000] [ key#2 state=S_UNDEF id=0 sid=00000000 00000000]
    Jun 20 20:01:24 openvpn 23836 TUN READ [56]
    Jun 20 20:01:24 openvpn 23836 TLS Warning: no data channel send key available: [key#0 state=S_PRE_START id=0 sid=00000000 00000000] [key#1 state=S_UNDEF id=0 sid=00000000 00000000] [ key#2 state=S_UNDEF id=0 sid=00000000 00000000]
    Jun 20 20:01:24 openvpn 23836 TUN READ [48]
    Jun 20 20:01:24 openvpn 23836 MSS: 1460 -> 1287
    Jun 20 20:01:24 openvpn 23836 TLS Warning: no data channel send key available: [key#0 state=S_PRE_START id=0 sid=00000000 00000000] [key#1 state=S_UNDEF id=0 sid=00000000 00000000] [ key#2 state=S_UNDEF id=0 sid=00000000 00000000]

  • AEAD Decrypt Error with OpenVPN

    1
    0 Votes
    1 Posts
    461 Views
    No one has replied
  • ovpn obfuscation

    9
    0 Votes
    9 Posts
    2k Views
    H

    @michmoor In any case, thank you for your help. Many thanks

  • [Solved] Can't resolve hostnames from OpenVPN Client

    4
    0 Votes
    4 Posts
    3k Views
    GertjanG

    @zapador said in [Solved] Can't resolve hostnames from OpenVPN Client:

    All of these resources (VPN clients) are vessels/ships with monitoring systems onboard that collect data

    👍
    Ah, nice, I get it.
    Collecting data from ships ... Nice !

  • TLS Error in OpenVPN

    5
    0 Votes
    5 Posts
    463 Views
    B

    @viragomann
    Yes, the failed and successful users are related to the same ISP. This is giving me no way out as OpenVPN clients are generated with the same settings for connecting to the server. Some connect and some don't, giving this TLS error.

  • I updated PFSense from 2.4.0 to 2.5.2 and iOS no longer connects

    9
    0 Votes
    9 Posts
    970 Views
    T

    @bingo600The IPV4 tunnel option is blank. Could that be the problem there?
    tunnel_.png

  • OpenVPN (Road Warrior) fills up SWAP

    1
    0 Votes
    1 Posts
    230 Views
    No one has replied
  • How to find OpenVPN DHCP leases on pfSense

    6
    0 Votes
    6 Posts
    981 Views
    GertjanG

    @aldomoro

    Ok, thank for the feedback.

    I've no 'Eset', and said goodbye to the 'antivirus' world many years ago.
    I use 'pfSense' as my network inventory tool 😊

  • OpenVPN site to site works with shared key but doesn't with SSL/TLS

    3
    0 Votes
    3 Posts
    478 Views
    G

    @viragomann It really worked just by changing the tunnel mask
    3a0337c6-5a1a-47ec-860f-764d5fc128f0-image.png

    Thanks a lot mate!

  • [solved] Netgate 8200 + OpenVPN with and without DCO problem

    2
    0 Votes
    2 Posts
    501 Views
    S

    My configuration dated from version 22.01 and then I went from version to version, now in 23.05 activating "DCO" and "QAT" on my 8200 crashed "UNBOUND".
    I completely redid the "Wizard" and now I can activate "DCO" and "QAT" and everything works. I've taken all the "information" from my old setup, but well ... one more mystery!

  • client-connect/client-disconnect scripts bypassed/overwritten

    1
    0 Votes
    1 Posts
    195 Views
    No one has replied
  • OpenVPN Connect - Clients have it on when on premises

    9
    0 Votes
    9 Posts
    1k Views
    T

    Yup. The rule blocking openvpn from the LAN side is what I have to do for the same reason. Without the rule, the VPN would connect and cause strange network connectivity issues. With the rule, the VPN doesn't work and it's easier to troubleshoot.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.