• OpenVPN GUI log doesn't display old messages

    1
    0 Votes
    1 Posts
    274 Views
    No one has replied
  • OpenVPN DCO with 23.01

    2
    0 Votes
    2 Posts
    520 Views
    S

    @mikey_s I haven’t had the opportunity to try it yet but per https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/dco.html:

    “Thus, DCO is beneficial even when only one endpoint is capable of DCO. That said, tunnels employing DCO on all peers will see the most benefit. With DCO on only one peer the performance improvement can still be notable but not as significant as the gains with DCO support on both endpoints.”

    That page also says it’s (still) experimental.

  • OpenVPN failover

    5
    0 Votes
    5 Posts
    654 Views
    D

    @viragomann Thank you so much. Yes. I did setup the gateway monitoring and indeed that was the fix. Need to set the default gateway to the multiwan gateway group i created.

  • Close port for client OpenVPN

    1
    0 Votes
    1 Posts
    203 Views
    No one has replied
  • OpenVPN Failed to Start

    14
    1 Votes
    14 Posts
    3k Views
    C

    @thomas_br Really wish there was a real solution for this. Sure I need to upgrade my device, but I also have a problem right now that Netgate is aware of but has made no effort to resolve without further service impact.

  • OpenVPN could not be established after upgrade to 23.01 on SG-2100

    1
    0 Votes
    1 Posts
    589 Views
    No one has replied
  • Problem authenticating to Active Directory LDAP server

    1
    0 Votes
    1 Posts
    526 Views
    No one has replied
  • OpenVPN with LDAP User groups

    6
    0 Votes
    6 Posts
    4k Views
    jimpJ

    A few weeks ago I went through and tested LDAP auth with extended query in a few different LDAP setups with/without RFC2307 groups and updated the docs with better info on that and using multiple server entries limited by groups for these sorts of purposes.

    If you haven't reviewed the docs recently, look them over again.

    https://docs.netgate.com/pfsense/en/latest/usermanager/ldap.html

    https://docs.netgate.com/pfsense/en/latest/troubleshooting/authentication.html

    Also I highly recommend using an LDAP browser such as Apache Directory Studio to test your queries and settings to dial in getting the results you want.

  • Flapping caused by rc.gateway_alarm & check_reload_status

    1
    0 Votes
    1 Posts
    255 Views
    No one has replied
  • OpenVpn Broke down

    1
    0 Votes
    1 Posts
    211 Views
    No one has replied
  • Troubleshooting OpenVPN?

    23
    0 Votes
    23 Posts
    2k Views
    V

    @jims
    The traffic doesn't go through the WAN interface in a logical way. It is tunneled and come in on the OpenVPN interface in pfSense.
    Also the traffic cannot pass through a LAN device by default. This would require special settings on the device. Since I assume, you control this device, you can be sure that they are not done.

    The whole security depends on the VPN authentication, regardless how you realize the access to the LAN devices. The server is under your control, you say, so use strong password and client certificates and you're safe.
    On pfSense you can additionally configure, what the clients are allowed to access.

  • OpenVPN local user lockout policy

    3
    0 Votes
    3 Posts
    733 Views
    G

    To answer this myself - I do not think OpenVPN user authentication failures from the pfSesne local database causes account lockout. SSH and Web UI failed logins will cause the source of the connection to be temporarily added to the block list.

    @jimp just answered this (as I type) to say it does not lockout the local database users.

    I have found, with help from Lawrence Systems videos (Tom L is a legend, n'est pas?) I can install FreeRadius package, and enable mobile one-time-passwords, add Radius users with OTP and get two benefits - disable accounts that fail to authenticate AND MFA/OTP.

    This satisfies UK Cyber Essentials, and I have a much stronger login process. Today is a good day.

  • OpenVPN client unable to reach LAN

    5
    0 Votes
    5 Posts
    649 Views
    P

    Solved it, and now I can ping LAN IPs and do RDP etc. It was the devices on my LAN were not using the pfsense IP as their gateway, but a different gateway device. I didnt think all the target devices on the inside of the network needed the pfsence box as their gateway. It makes sence now.
    Also, a gateway IP is still not present for the openVPN connection, but connection to LAN devices and to the internet is working normally despite this.

  • 0 Votes
    7 Posts
    1k Views
    D

    @viragomann

    I appreciate your help, it pushed me in the right direction, there must indeed have been my ISP router out in the street box/head office. My WAN was using a private IP address with I assume the public IP address at my ISP router.

    I believe that traffic was hitting my Pfsense router but the outbound traffic was not being NAT'd correctly by the ISP router.

    Anyway, I upgraded to have a public IP on my router which resolved the issue.

  • workaround network conflict host to remote (both are 192.168.1.x)?

    11
    0 Votes
    11 Posts
    1k Views
    JKnottJ

    @chpalmer

    That is a very common problem caused by the need to use NAT & RFC1918 addresses with IPv4.

    Back in the early 90s, when I first started using the Internet, I had a static address, I was using SLIP, which required manual configuration. In 1997, I started at IBM, and had 5 static, public addresses, 1 for my own computer and 4 for testing. A couple of years later, when I got a cable modem and built a firewall/router on Linux, I ran into my first problem caused by NAT. FTP broke! Back then, command line FTP was used and NAT broke active mode FTP. At the time, FTP clients generally didn't support passive mode. These days, things like VoIP and some games require a hack called STUN, to get around the problems caused by the hack called NAT.

    The answer to this is IPv6!

  • OpenVPN toggle on / off

    5
    0 Votes
    5 Posts
    1k Views
    R

    @sfermindi bear in mind those instructions are from a release from 2018. Things do change.

  • 0 Votes
    2 Posts
    311 Views
    GertjanG

    @owlbear

    If you don't mind a video, you can get one form the source :

    Configuring OpenVPN Remote Access in pfSense Software

  • OpenVPN Connect Connection Issues

    1
    0 Votes
    1 Posts
    471 Views
    No one has replied
  • OpenVPN set up questions

    7
    0 Votes
    7 Posts
    819 Views
    O

    @viragomann you had it right they didn't show up because there were no user certificates. So my configuration wasn't complete.

  • 0 Votes
    4 Posts
    604 Views
    J

    @jims Spoke too soon. It now shows it reconnects but all the traffic isn't passed. I can get to one of my PCs through the VPN but can't get to others, even after rebooting pfsense. Thought it was something to do with the other PC so tried another and even a printer than has a web page and no go. Not sure what to check now...

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.