Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Local authentication with groups of users

    Scheduled Pinned Locked Moved OpenVPN
    4 Posts 2 Posters 546 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • PPCMP
      PPCM
      last edited by

      Hello there,

      I need to have multiple OpenVPN servers, on each of them, the list of users is different.
      Previously, I used an AD authentication and MemberOf filters, but now I need to use the Local Database of pfSense

      I saw that there is a possibility to use groups with local users, but I didn't find how to use it with OpenVPN

      Does somebody know?
      Thanks for any help

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @PPCM
        last edited by

        @ppcm
        Create a CA for each OpenVPN server and generate the server cert and client certs with it.
        So the clients can only connect to that server which has the proper CA assigned to.

        PPCMP 1 Reply Last reply Reply Quote 0
        • PPCMP
          PPCM @viragomann
          last edited by

          @viragomann Thanks for the answer, but in this case, the user need it's cert in client config, and if the user changes groups, I will need to send a new config, not easy to manage
          One more thing, a user can be associated with only one OpenVPN

          Is there a way to use groups of pfSense?

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @PPCM
            last edited by

            @ppcm said in Local authentication with groups of users:

            if the user changes groups, I will need to send a new config, not easy to manage

            I'm running multiple OpenVPN servers with different CAs for different user groups for 10 years. Never need to move a user into another group till today.

            Is there a way to use groups of pfSense?

            No, not the local user groups in OpenVPN.

            If you need to replace the functionality of AD you can install the FreeRADIUS package and use it in the OpenVPN servers for authentication.
            Authenticating OpenVPN Users with FreeRADIUS

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.