Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DEPRECATED OPTION: --cipher set to 'AES-256-CBC' etc.

    Scheduled Pinned Locked Moved OpenVPN
    14 Posts 4 Posters 13.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator @Cabledude
      last edited by

      @cabledude while 256 is more secure.. My vpn connection sure isn't a DoD setup or anything ;)

      Was me playing around at some point I am sure - I also limit vpn access to only US, and also have tls set to auth and encryption.. No worried about someone break AES-128-GCM ;) heheh

      Was prob me setting it up with multiple levels, and then limiting what I could use on the client and make sure still get in, etc.

      I will have to see if I can duplicate what you saying about it not saving.. I will do that in the morning..

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • C
        Cabledude
        last edited by

        Dear @johnpoz : I would not dream of criticising your work, as I am way too humble re pfSense. I may have put my question with poor eloquence, sorry for that :)

        Limiting VPN access based on GeoIP sounds like genius. May I ask how that is done? pfBlocker? Or is this customisable in the VPN settings?

        Thanks,
        Pete

        Pete
        Home: SG-2100 + UniFi + Synology. SG-1100 retired
        Parents: SG-1100 + UniFi + Synology
        Testing: SG-1100 w/ 120GB SSD via ext USB (eMMC dead). Works great

        johnpozJ 1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @Cabledude
          last edited by johnpoz

          @cabledude use of alias in pfblocker - setup one with the US.. Use that in the rule that allows access to vpn port on wan.

          I may have put my question with poor eloquence, sorry for that :)

          Not in any way - a very valid question..

          edit: And I just ran through the wizard, and your right it does look like it should be enabled by default (check box is checked and 3 listed to be used). But then after the wizard if you look at the settings its not checked? Hmmmm??

          wizard.jpg

          That seems like some sort of issue to me.. Have to look into redmine and see if has been reported..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          C 1 Reply Last reply Reply Quote 0
          • C
            Cabledude @johnpoz
            last edited by

            @johnpoz thank you for sharing the geoip method. I will look into it as soon as I have some time.
            Glad it’s not just me re the checkbox. For me it’s not an issue anymore as I now know where to look, but I’ve been scratching my head for a while 😅

            Pete
            Home: SG-2100 + UniFi + Synology. SG-1100 retired
            Parents: SG-1100 + UniFi + Synology
            Testing: SG-1100 w/ 120GB SSD via ext USB (eMMC dead). Works great

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @Cabledude
              last edited by johnpoz

              @cabledude said in DEPRECATED OPTION: --cipher set to 'AES-256-CBC' etc.:

              for sharing the geoip method.

              If you need more help on that just ask.

              Yeah playing with it a bit - and the check box for negotiation does seem wrong to me. And for sure could confuse new users I think. I even tried toggling it in the wizard and still doesn't seem to actually set it..

              You have to actually go into the settings and toggle it.. Possible oversight in the wizard code.. I don't see anything that I can find about it in redmine.

              Lets call in @stephenw10 and @jimp see if overlooking something - if not I can put in a redmine about it.

              Maybe I need more coffee this morning but from the wizard showing that checked, and 3 algos selected it would sure seem to me that is what should be set. But when you go into the server settings, the algos are there, but the checkbox is not checked.

              edit: ah it is thanksgiving, they with family and friends I hope vs reading forum posts ;) like us! hehehe

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              C 1 Reply Last reply Reply Quote 0
              • C
                Cabledude @johnpoz
                last edited by Cabledude

                @johnpoz Never could have guessed that a simple beginner like myself could spark this level of attention 😀

                And maybe I should learn how to drink coffee (at 52)… 😉

                Edit oh yes thanksgiving! I heard about that when I talked to my cousin in San José. I am living in the Netherlands so no thanksgiving here…

                Pete
                Home: SG-2100 + UniFi + Synology. SG-1100 retired
                Parents: SG-1100 + UniFi + Synology
                Testing: SG-1100 w/ 120GB SSD via ext USB (eMMC dead). Works great

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @Cabledude
                  last edited by johnpoz

                  @cabledude said in DEPRECATED OPTION: --cipher set to 'AES-256-CBC' etc.:

                  Netherlands so no thanksgiving here…

                  Well not a national sort of holiday.. But is there not Dankdag, November 3rd I believe?

                  I believe some of the pilgrims that first came to America did have a long "layover" in the Netherlands ;) In Leiden early 1600s I do believe. And I think they hold some sort of something at Pieterskerk on US turkey day ;)

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  C 1 Reply Last reply Reply Quote 0
                  • C
                    Cabledude @johnpoz
                    last edited by

                    @johnpoz I had to look that up, amazing how I can be taught this kind of stuff about our history by someone not living even close! Yes so it’s a religious act in which we say thanks for crop and labour. Apparently it is still practised today.
                    The pilgrims, yes, you’re quite right there too. Around 1620 in leiden. I went to school in leiden! My home area.

                    Pete
                    Home: SG-2100 + UniFi + Synology. SG-1100 retired
                    Parents: SG-1100 + UniFi + Synology
                    Testing: SG-1100 w/ 120GB SSD via ext USB (eMMC dead). Works great

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      I was able to replicate this in 2.5.2 but it looks like it's already fixed in 2.6 so there's little point in opening a bug for it at this point.

                      Steve

                      C 1 Reply Last reply Reply Quote 2
                      • C
                        Cabledude @stephenw10
                        last edited by

                        @stephenw10 I give thanks for you having a look 😀

                        Pete
                        Home: SG-2100 + UniFi + Synology. SG-1100 retired
                        Parents: SG-1100 + UniFi + Synology
                        Testing: SG-1100 w/ 120GB SSD via ext USB (eMMC dead). Works great

                        1 Reply Last reply Reply Quote 1
                        • jimpJ
                          jimp Rebel Alliance Developer Netgate
                          last edited by

                          Ditto. I couldn't replicate it on 2.6.0 / 22.01.

                          Looks like it was fixed by https://redmine.pfsense.org/issues/12172

                          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                          Need help fast? Netgate Global Support!

                          Do not Chat/PM for help!

                          1 Reply Last reply Reply Quote 1
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.