Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN - Remote Access User Auth still broken in 2.5.2?

    Scheduled Pinned Locked Moved OpenVPN
    14 Posts 4 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG
      Gertjan @andyhi
      last edited by Gertjan

      @andyhi

      if "User Auth" was broken, then all devices using current CE and Plus couldn't be used to "home work", or just simple remote access.

      That alone would trigger an emergency update - or at least a patch.

      Btw : what about skipping "User Auth", go for TLS only.
      I know that works, as I'm using it right now.

      @andyhi said in OpenVPN - Remote Access User Auth still broken in 2.5.2?:

      I ran across it a day or so after upgrading a BYOD box to v2.5.0 and had to use the same fix

      2.5.0 is old, was a huge milestone and had some issues.
      2.5.2 is what you need - you don't want to test drive old bugs ;).

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      A 1 Reply Last reply Reply Quote 0
      • A
        andyhi @Gertjan
        last edited by andyhi

        @gertjan said in OpenVPN - Remote Access User Auth still broken in 2.5.2?:

        @andyhi

        if "User Auth" was broken, then all devices using current CE and Plus couldn't be used to "home work", or just simple remote access.

        That alone would trigger an emergency update - or at least a patch.

        Wrong - Many people appear to be using TLS based auth only instead of TLS + User Auth (TLS + User Password).

        Btw : what about skipping "User Auth", go for TLS only.
        I know that works, as I'm using it right now.

        Yeah, that's what I stated in my original post... TLS based auth works. TLS + "User Auth" (TLS + password) and "User Auth" (password only) does not... at least on my SG-1100 and one of my BYOD builds. The "User Auth" (password) option quit working on both after a prior version upgrade and started working again with no changes on my end for the SG-1100 after a recent v2.5.2 upgrade... but is still broken on the BYOD device which is also on v2.5.2.

        As for TLS only vs TLS + user password - TLS + User Auth is more secure. (Technically it's 2FA - Something you have and something you know.) The TLS cert / private key are sitting on the client in the file system (assuming smart card / HSM isn't being used) and subject to be stolen while at rest at any point. This could potentially be by malware or if you lose physical control of the asset. Assuming you key the password in at every login and don't check the store password option - The user password portion is only subject to be stolen if the password or it's hash is stolen from memory by the threat actor... so exploitation opportunity is still there but significantly reduced by using the TLS plus User password option and not saving the password to the file system on the client.

        @andyhi said in OpenVPN - Remote Access User Auth still broken in 2.5.2?:

        I ran across it a day or so after upgrading a BYOD box to v2.5.0 and had to use the same fix

        2.5.0 is old, was a huge milestone and had some issues.
        2.5.2 is what you need - you don't want to test drive old bugs ;).

        Perhaps the timing of up upgrades wasn't clear. I upgraded to 2.5.0 early in the year - Late Feb / Early March a week or two after release. Given the issues with v2.5 for CE and Plus - I was slower to upgrade to the 2.5.1 and 2.5.2 code bases.

        At this point I do suspect at least some people have TLS + User Auth (password) working as that's the default config for new setups and noone appears to be reporting similar issues. When I get some free time after the holidays I'll spin up some pFsesnse VMs from scratch to see what's going on... perhaps import a back up of the broken BYOD device and try a fresh OOB install with 1st time CA, certs, + open vpn config.

        GertjanG 1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan @andyhi
          last edited by Gertjan

          @andyhi said in OpenVPN - Remote Access User Auth still broken in 2.5.2?:

          Wrong - Many people appear to be using TLS based auth only instead of TLS + User Auth (TLS + User Password).

          What's wrong ?
          If "User Auth" was broken, then we would / should would see posts on the forum about it. OpenVPN server usage became last year a extremely important feature, we all know why.
          .I presume that "User Auth" (or "User Auth" combined with TLS) is very often used.

          Myself, I'm not using "User Auth", only TLS, as I'm using the pfSense OpenVPN server access just for maintenance reasons and some minor administration tasks.

          edit :
          I've set up a "user auth" OpenVPN server on my WAN interface, port 1195 UDPv4.
          cdb0682e-e12e-4570-bcdb-215b5cc96658-image.png

          Assigned a not-yet-used IPv4 network 192.168.4.0/24

          edit2 :
          That is, I instantiated the 'virtual' interface created by my second '1195' OpenVPN as an interface and called it OPENVPNAUTH :

          7e4fa930-adb2-49a2-aa5a-a430341c0c0e-image.png

          Created a main pass rule firewall rule on this OPENVPNAUTH :

          eba62cbe-5c0d-4516-8472-840f2cf378b3-image.png

          Created a firewall rule on WAN so UDP port 1195 traffic can come in :
          06edd2f4-409a-4654-83d5-ae4405e8337e-image.png

          Created a Nat/firewall in my ISP router ("port 1195 UDP4 to IP WAN pfSense" )

          Created a OpenVPN user :

          a93899d0-4c1b-4162-8650-695874629a88-image.png

          Exported the user config file( I had to select the "1195" openvpn server instance ) :

          ea3cd332-04fd-4650-bf60-6ecc59fcf3eb-image.png

          Imported the file in my iPhone.
          While doing so, added a user name "vpn" and password "***".

          I could connect just fine, using "User Auth" only.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          bingo600B 1 Reply Last reply Reply Quote 1
          • bingo600B
            bingo600 @Gertjan
            last edited by

            I'm using TLS + User Auth for my "Roadwarroirs"
            AKA .. 4096bit Certs + UID/PWD

            It would be a major disaster if it does not work , when i upgrade my Central pfSense to 2.5.2.

            So i'm quite interested in this thread

            /Bingo

            If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

            pfSense+ 23.05.1 (ZFS)

            QOTOM-Q355G4 Quad Lan.
            CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
            LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @bingo600
              last edited by

              @bingo600 said in OpenVPN - Remote Access User Auth still broken in 2.5.2?:

              So i'm quite interested in this thread

              Same here - I spend way to much time here ;) And I would of thought I would of noticed this thread where jimp confirmed an issue, but no bug report? I can not seem to find anything in redmine related to this.

              And also agree, that if something like this broke - I would think there would be many a post about it.. Its a common sort of setup, etc.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              GertjanG 1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan @johnpoz
                last edited by

                @johnpoz said in OpenVPN - Remote Access User Auth still broken in 2.5.2?:

                Its a common sort of setup, etc.

                "Common" means you know what to do. And the thing is, that's not 'common'.

                Setting up a bare minimum 'OpenVPN server' supporting 'user auth', implies several steps.
                I even had to 'punch' a hole into my upstream ISP router, something I completely forgot during several minutes, but then the palm of my hand went straight to the front of my head etc.

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @Gertjan
                  last edited by

                  @gertjan said in OpenVPN - Remote Access User Auth still broken in 2.5.2?:

                  'OpenVPN server' supporting 'user auth', implies several steps.

                  Concur there are more steps than just tls auth, but tls+auth is default using the wizard, to why I stated common.

                  default.jpg

                  The wizard didn't even ask the question..

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  GertjanG 1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan @johnpoz
                    last edited by

                    @johnpoz

                    I learned something : there is a wizard !

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @Gertjan
                      last edited by

                      @gertjan said in OpenVPN - Remote Access User Auth still broken in 2.5.2?:

                      there is a wizard

                      hahaah ;)

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      bingo600B 1 Reply Last reply Reply Quote 0
                      • bingo600B
                        bingo600 @johnpoz
                        last edited by bingo600

                        @johnpoz said in OpenVPN - Remote Access User Auth still broken in 2.5.2?:

                        @gertjan said in OpenVPN - Remote Access User Auth still broken in 2.5.2?:

                        there is a wizard

                        hahaah ;)

                        I've never used a wizard for making VPN's.
                        I'd like to be in control.

                        Or ... Did I just miss you being procounced : The Gandalf of pfSense ??

                        /Bingo

                        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                        pfSense+ 23.05.1 (ZFS)

                        QOTOM-Q355G4 Quad Lan.
                        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                        johnpozJ 1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @bingo600
                          last edited by

                          @bingo600 said in OpenVPN - Remote Access User Auth still broken in 2.5.2?:

                          The Gandalf of pfSense ??

                          hahah - no unless I missed the ceremony myself? ;)

                          The wizard is just a easy way to get a basic remote access vpn up in running in a few clicks. You can always edit the settings how you see fit after. It will even walk you through creating the CA and certs, etc.. Its a great little tool for someone new to setting up a vpn.. Will create the firewall rule for you, etc.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.