• OpenVPN Slow Only on One Specific Client (2.5G/1G Network)

    5
    0 Votes
    5 Posts
    349 Views
    GertjanG

    @Aadrem said in OpenVPN Slow Only on One Specific Client (2.5G/1G Network):

    Super Micro 1537 with a CPU that never exceeds 10% load,

    pfSense is waiting on the WAN interface for traffic that comes in. Other VPN users have no issue, and you're pfSense handles them just fine. Just this 'one more' shows issues ?
    So, the issue isn't pfSense, the VPN server ..... but the client, or the connection to/from the client.

    What happens if you swap the VPN client config between 2 of your VPN users ?

    @Aadrem said in OpenVPN Slow Only on One Specific Client (2.5G/1G Network):

    (2.5 Gbps download / 1 Gbps upload). They are not on mobile 5G or a limited connection

    No need to mention this, if you already know the hard sealing :
    (1 Gbps download / 300 Mbps upload)

    That said, the "problematic clients are a MacBook Pro and a OnePlus" have the connection "(2.5 Gbps download / 1 Gbps upload)" all for themselves ? Or is this connection shared with others ?
    ISPs do sell their speeds measured with special conditions : like sun, Mars Earth and Jupiter aligned.

    @Aadrem said in OpenVPN Slow Only on One Specific Client (2.5G/1G Network):

    The issue does NOT occur when using 5G or FTTC connections, only on this specific FTTH connection.

    Ah : That's useful info. The issue points to that network and the ISP.

  • Any Suggestions: Frequent Disconnects/Reconnects

    1
    0 Votes
    1 Posts
    169 Views
    No one has replied
  • pfsense openvpn client to ubuntu server connects but wont reconnect

    10
    0 Votes
    10 Posts
    1k Views
    A

    @Gertjan
    in case anyone has this issue, i found the solution. besides removing the DNS line remove the TLS key from Custom options under advanced configuration towards the bottom of the openvpn client. then go to the top and select USE A TLS KEY, then uncheck automatically generate a key and paste your key from your server here.
    then for TLS Key Usage Mode change it to TLS encryption and authentication.
    now it works after saving the changes!

  • OpenVPN can only connect to HTTPS on gateway

    12
    0 Votes
    12 Posts
    806 Views
    CatSpecial202C

    @viragomann Sorry for that. Yes, it looks like there was a misconfiguration here. I had to change my default gateway it was still setup to be the 10.0.0.1 that the switch comes with. I thought it would be set from DHCP but i guess it wasn't. It's all working now! Thanks!

  • VPN with dual wan failovr

    1
    0 Votes
    1 Posts
    100 Views
    No one has replied
  • Openvpn and cisco-avpair - attributes check

    1
    0 Votes
    1 Posts
    146 Views
    No one has replied
  • 0 Votes
    7 Posts
    474 Views
    V

    @poldus
    What do you consider as "static" here?

    The above shows the client log. But what shows the server log?
    Does the server even see any VPN packet?

    Are you aware, that shared key OpenVPN is deprecated these days?

    Do you really intend to setup a tap client?

  • No connection after certificate renewal

    1
    0 Votes
    1 Posts
    203 Views
    No one has replied
  • OpenVPN tunnel beetween sites and TFTP provisionning

    12
    0 Votes
    12 Posts
    841 Views
    V

    @guillaume14
    Ensure all related states are flushed.

    If the no-nat rule still isn't applied, there might something wrong in its settings, so that it doesn't match.
    Ensure that the protocol and the destination port are correct if stated.

  • Local address pending

    1
    0 Votes
    1 Posts
    102 Views
    No one has replied
  • OpenVPN regression pushing wrong subnet mask in route to client

    1
    0 Votes
    1 Posts
    114 Views
    No one has replied
  • 0 Votes
    3 Posts
    350 Views
    johnpozJ

    @rajukarthik its just the normal openvpn community edition.

    [2.7.2-RELEASE][admin@test.mydomain.tld]/root: openvpn --version OpenVPN 2.6.8 amd64-portbld-freebsd14.0 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [MH/RECVDA] [AEAD] [DCO] library versions: OpenSSL 3.0.12 24 Oct 2023, LZO 2.10

    Yeah it is a bit dated, sure that will update when 2.8 drops.. but its not the access server version.

    As to soc2 - As to the just community edition, prob not - since really the user of said edition can pretty much do anything they want with the config, were with the AS and Cloud versions of their server being more strictly controlled in what can be configured.

    Those 2 versions are not free, so sure they can get certification of meeting specific standards, etc. But I doubt they would run through such trouble with audits of controls, etc. for something the user might easy override even a config change.

    If you really want to make sure its soc2 compliant - I would run either of those on something other than pfsense. I have not heard of anything about being able to run say the as version on pfsense.

    I run an as version on one of my vpses - you can run it for free for max of 2 concurrent connections. Which for me is plenty for my use case.

  • Openvpn : assign a fixed ip to a user included in a ldaps group

    1
    0 Votes
    1 Posts
    99 Views
    No one has replied
  • OpenVPN Renegotiation Time with MFA

    3
    0 Votes
    3 Posts
    260 Views
    R

    @bozo-bogd

    We tried setting reneg-sec on both sides to 0 but it caused the client to constant want the MFA prompt satisfied. The pings settings are already set to 0

    Details from Azure. We have a CA policy that requires MFA when authenticating to the EntraID account. The Entra RADIUS VPN app is installed on our RADIUS box to interject the MFA prompt when authenticating to our local AD with the OpenVPN client. The MFA app has a limited config, with caching and renegotiation settings not being options.

  • OpenVPN wiht EntraID (Directly)

    1
    0 Votes
    1 Posts
    140 Views
    No one has replied
  • Not using OVPN however OVPN is logging errors

    4
    0 Votes
    4 Posts
    210 Views
    johnpozJ

    @McMurphy hahah - yeah minor detail ;) hehehe

  • OpenVPN malfunctioning due to MTU

    2
    0 Votes
    2 Posts
    779 Views
    D

    @DSTMalo Thank you so much! Happy new year.

  • CRL has expired

    29
    0 Votes
    29 Posts
    8k Views
    J

    @Gertjan perfect thank you. Still shows as applied and has the revert option so i'll keep it applied

  • HA Setup - Cannot Access 2nd node via OpenVPN

    3
    0 Votes
    3 Posts
    200 Views
    Z

    Perfect. Thank you

  • OpenVPN site-to-site communication issue

    11
    0 Votes
    11 Posts
    637 Views
    M

    @viragomann It works!

    I remove the client static IP configuration from the server setup and ping works from both sides.

    It was quite difficult but the reason why I didn't read the documentation about s2s OpenVPN connection. Thank you!

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.