• PfSense 1.2.3 site-to-site client OpenVPN tunnel fails to restart

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    C
    If you touch an assigned tun interface on 1.2.3, you must edit and save the associated OpenVPN client or server before it will function again (which will restart it). That works fine.
  • OpenVPN site-to-site dual-wan on one side with AUTOMATIC failover?

    Locked
    4
    0 Votes
    4 Posts
    13k Views
    jimpJ
    That should work fine, I've done that a time or two in the past.
  • Star topology with extra tunnel between two remote offices

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Strange ping on pfsense 2.0 openvpn

    Locked
    11
    0 Votes
    11 Posts
    5k Views
    jimpJ
    Bridging is ugly and really isn't needed. Firewall > NAT, Outbound NAT tab Switch to manual outbound NAT, press save. Add a rule, interface is LAN, source address would be your VPN subnet. Destination would be your LAN subnet, translation address would be 'Interface Address'. That should be enough
  • 0 Votes
    20 Posts
    14k Views
    O
    yes i pushed the wins server throw the tunnel to vpn-clients. i test it tonight thanks for tipps havok
  • Pfsense does not route through the openvpn tunnel [solved]

    Locked
    6
    0 Votes
    6 Posts
    12k Views
    M
    Thank you very very much! Could not see the wood for the trees….
  • OpenVPN tcp AND udp | using bridge as interface?

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Cryptography- Can it be changed and how?

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    M
    Success!  Thanks CMB!  That makes sense; I guess I just happened to luck out that the client had the same default cipher as pfSense.  Now to work the magic with a DD-WRT router; I've heard they are a bear to get working.
  • Removing auto added rules + ns-cert-type issues

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    0
    After having thought a bit more about the wordings in pfSense book at 15.6.2 I believe I may have made the incorrect assumption. It looks like one may at any time enable or disable them using that setting at System | Advanced. If this is the case, can someone help my understand why the FW rules for the interface isn't working? TIA,
  • Can't delete or edit OpenVPN connection!

    Locked
    5
    0 Votes
    5 Posts
    13k Views
    0
    @jimp: The files in /var/etc should not be touched. They are created by the system from the data in the config, and those are what openvpn uses while it's running. As for the config entries that can't be deleted, there is a bug in 1.2.x that sometimes causes a stray "<config>" tag in certain areas. If the blank entries are a problem, just make a backup of the config, find the "<config>" tag under the openvpn server and client settings, and restore the edited config.</config></config> Ok, thanks, will make a note of this.
  • Username and password

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Restrictions in OpenVPN

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    X
    Bumps require payment to pfsense team if done less than 24 hrs  ;) So the one that is not working, does it even connect? If not look at the config files make sure they match on both sides.
  • OpenVPN All Traffic Routing

    Locked
    7
    0 Votes
    7 Posts
    9k Views
    S
    Thanks it worked!
  • OpenVPN Interface in pfsense 2.0

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    O
    jaja - das ist ja geradewegs perfekt! manchmal sieht man den wald vor lauter…. DANKEEE
  • Custom Config help needed: Multiple subnets *ANSWERED*

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    J
    @jimp: No, if it's PKI then you can push and you fill out local and remote networks normally. You really should just need the proper routes then. Most people don't do PKI for site-to-site which is why I mentioned the other limitation. Thanks, the information you provided helped tremendously.  Now that I understand the routing and limitations of shared key, it all makes perfect sense.  Everything works as expected now.
  • Confused about OpenVPN Site to Site IP address (CIDR Route Summarization)

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • OpenVPN site-to-site DNS problem

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • WLAN / tunneling data traffic from clients till pfSense-box possible?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    Cry HavokC
    No, it means that when you run a VPN (encrypted tunnel) you need higher specification hardware to handle the bandwidth - regardless of your choice of platform. A box that can handle 50 Mb/s of unencrypted traffic may have problems with 10 Mb/s of encrypted traffic. A lot will depend on what VPN technology you use, what level of encryption you decide upon etc.
  • Can I limit sessions per login?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    S
    hi, so there is no way the server can deny a second connection with same certificate? cya
  • OpenVPN Tunnel Network

    Locked
    3
    0 Votes
    3 Posts
    9k Views
    jimpJ
    Vayatta may config their openvpn servers differently (perhaps using tap rather than tun). You can use any non-overlapping RFC1918 (or even public if you really want) block for the address pool, but the way OpenVPN assigns addresses (it carves /30's out of that /24) is well documented by OpenVPN: http://openvpn.net/index.php/open-source/faq/77-server/273-qifconfig-poolq-option-use-a-30-subnet-4-private-ip-addresses-per-client-when-used-in-tun-mode.html
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.