Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN clients problems

    Routing and Multi WAN
    3
    7
    892
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • U
      Uzzi78
      last edited by

      Hi, i've a new pfsese installation.
      wan--->external Fortigate--->internet
      lan---->internal subnets
      Openvpn server on pfsense

      All openvpn clients, are negotiating correctily with server, but cannot navigate to internals subnets.
      Where can I see why? Firewall logs aren't helping me.
      What could be the problem?

      Thank you

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @Uzzi78
        last edited by

        @uzzi78

        @uzzi78 said in OpenVPN clients problems:

        Firewall logs aren't helping me.

        Maybe they could, if you let them do so.

        During test phase, check this option :

        67423fb3-ac85-4d07-8b3d-d18426c98239-image.png

        Now default (hidden) block rules will also log.
        Test again with a VPN client. Can you see traffic (being blocked) now in the firewall log ?

        @uzzi78 said in OpenVPN clients problems:

        but cannot navigate to internals subnets

        No access to LANs - but can you access for example the pfSense admin interface ?
        The internet ?

        Do you use this "OpenVPN" interface :

        72ae657d-7937-4096-b139-651554d19e73-image.png

        Or have you assigned to the OpenVPN server interface an interface (mine is called OPENVPN here ) :

        0582c640-d117-4338-8e0f-3ab2bb7cdb1b-image.png

        On the interface used by the OpenVPN server, as it is an 'incoming' interface' there must be pass rules. I've entered a pass for IPv4 and IPv65, as i'm using both.

        Also : check your clients, for what OpenVPN version they are using.
        pfSense 2.5.2 is based on the "2.5.2" OpenVPN version. There are some minor changes, when compared to the older 2.4.x OpenVPN that was used before.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        U 1 Reply Last reply Reply Quote 0
        • U
          Uzzi78 @Gertjan
          last edited by

          Hi @gertjan , thank you

          I'm tryng to ping 172.16.6.111 from OpenVPN clients
          I have disabled Log firewall default bloks
          Schermata da 2022-01-11 10-56-18.png

          Schermata da 2022-01-11 11-00-36.png

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @Uzzi78
            last edited by

            @uzzi78 prob have compression setup wrong, not matching. Do you have comp-lzo set different on server vs client.. Compression really shouldn't be used currently.

            https://community.openvpn.net/openvpn/wiki/VORACLE

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            U 1 Reply Last reply Reply Quote 0
            • U
              Uzzi78 @johnpoz
              last edited by

              Thank you, now works fine.
              Can I notify when Openvpn clients are connected to server?

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @Uzzi78
                last edited by

                @uzzi78 how you mean notify - you can see right on the dashboard if clients are connected, etc.

                Just add the openvpn widget

                Are you looking for like an email? here is thread

                https://forum.netgate.com/topic/151351/email-notification-openvpn-client-connect-common-name/26

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                U 1 Reply Last reply Reply Quote 0
                • U
                  Uzzi78 @johnpoz
                  last edited by

                  Thank you
                  works fine

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.