Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN server on pfSense behind Starlink router in bridge mode

    Scheduled Pinned Locked Moved OpenVPN
    14 Posts 4 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rcoleman-netgate Netgate @LawRi
      last edited by

      @lawri Doesn't Starlink use CGNAT for it's IP blocks? If so you will need a 3rd system to do your bridging -- basically you connect to the 3rd device that also gets connected to via OVPN by the pfSense behind dishy.

      Same design applies to having a home LTE internet service that uses a CGNAT for configurations -- you need something to play the intermediary.

      Ryan
      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
      Requesting firmware for your Netgate device? https://go.netgate.com
      Switching: Mikrotik, Netgear, Extreme
      Wireless: Aruba, Ubiquiti

      L 1 Reply Last reply Reply Quote 0
      • chpalmerC
        chpalmer @LawRi
        last edited by

        @lawri

        Is the client behind CGNAT as well?

        Triggering snowflakes one by one..
        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

        1 Reply Last reply Reply Quote 0
        • L
          LawRi @rcoleman-netgate
          last edited by

          @rcoleman-netgate thanks for answer, I thought it might be something like that. Have to learn how to do that.

          @chpalmer no client is not behind CGNAT

          chpalmerC 1 Reply Last reply Reply Quote 0
          • chpalmerC
            chpalmer @LawRi
            last edited by

            @lawri said in OpenVPN server on pfSense behind Starlink router in bridge mode:

            @chpalmer no client is not behind CGNAT

            Could you make the client side the server side instead? I don't know your particular circumstance there so just throwing the idea out there.

            Triggering snowflakes one by one..
            Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

            R 1 Reply Last reply Reply Quote 0
            • R
              rcoleman-netgate Netgate @chpalmer
              last edited by

              @chpalmer said in OpenVPN server on pfSense behind Starlink router in bridge mode:

              Could you make the client side the server side instead? I

              If the client is using something like TMO home internet the routed IP will change regularly. Had that trouble at a friend's business last week when his FTTP broke.

              Ryan
              Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
              Requesting firmware for your Netgate device? https://go.netgate.com
              Switching: Mikrotik, Netgear, Extreme
              Wireless: Aruba, Ubiquiti

              chpalmerC 1 Reply Last reply Reply Quote 0
              • chpalmerC
                chpalmer @rcoleman-netgate
                last edited by chpalmer

                @rcoleman-netgate Wouldn't dynamic DNS work for that?

                Triggering snowflakes one by one..
                Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                R 1 Reply Last reply Reply Quote 0
                • R
                  rcoleman-netgate Netgate @chpalmer
                  last edited by

                  @chpalmer No because the routing IP on cellular networks almost never remains the same for more than a few seconds. If you think CGNAT is bad, this is 1000x times worse. DynDNS might be one 1 IP on moment and another the next.

                  Ryan
                  Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                  Requesting firmware for your Netgate device? https://go.netgate.com
                  Switching: Mikrotik, Netgear, Extreme
                  Wireless: Aruba, Ubiquiti

                  chpalmerC 1 Reply Last reply Reply Quote 0
                  • chpalmerC
                    chpalmer @rcoleman-netgate
                    last edited by

                    I do know that a customer of (at least Verizon) can get a public IP address assigned to their number.. This may now only be for commercial accounts but this might be a solution available from any of the carriers..

                    But according to LawRi> "no client is not behind CGNAT"

                    thus my comment that he could possibly put the server side on the "client" side.. and make his side the "client" side of the connection. Not sure why that couldn't work for him as I do it here for one of my radio sites..

                    Triggering snowflakes one by one..
                    Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                    1 Reply Last reply Reply Quote 0
                    • L
                      LawRi
                      last edited by

                      Thanks for all answers but I stopped using OpenVPN cause CGNAT.
                      Now I made cloudflare tunnel so client can connect directly to services it needs.
                      Client is me in office, server is me at home 🙂 .

                      wgstarksW 1 Reply Last reply Reply Quote 0
                      • wgstarksW
                        wgstarks @LawRi
                        last edited by

                        @lawri said in OpenVPN server on pfSense behind Starlink router in bridge mode:

                        Thanks for all answers but I stopped using OpenVPN cause CGNAT.
                        Now I made cloudflare tunnel so client can connect directly to services it needs.
                        Client is me in office, server is me at home 🙂 .

                        I’m going to be relocating (soon) to an area with no cable and very spotty cell phone coverage and planning to use Starlink for internet access since it’s really the only option and is expected to be available sometime this year. I use the OpenVPN server builtin to pfsense a lot to connect my iPhone back to my home network when I’m at work. Could you describe how you setup the cloudflare tunnel to access your network?

                        Box: SG-4200

                        L 1 Reply Last reply Reply Quote 0
                        • L
                          LawRi @wgstarks
                          last edited by LawRi

                          @wgstarks I watched a few videos on YT and made a tunnel for myself. There is free plan to sign for. You need a domain, if you don't have one you can buy one from them (10$ a year). Then you make new tunnel, you need local machine that is always connected to internet and install client on it. As I understand that client connects tunnel to Cloudflare. After that you expose some services to that tunnel, like NAT. You can protect your tunnel with few options, I used mail protection on each service. I watched this two videos
                          NetworkChuck
                          Lawrence systems

                          wgstarksW 1 Reply Last reply Reply Quote 0
                          • wgstarksW
                            wgstarks @LawRi
                            last edited by

                            @lawri
                            Thanks. I've seen that but I really need something I can run Plex through. It's my understanding that the Cloudflare ToS doesn't allow streaming through the tunnel.

                            Thanks for the video links though. I'm sure the process is basically the same for any endpoint.

                            Box: SG-4200

                            L 1 Reply Last reply Reply Quote 0
                            • L
                              LawRi @wgstarks
                              last edited by

                              @wgstarks I don't use Plex for home streaming, and generally I didn't expose my home cinema server to tunnel. I looked at Cloudflare Tos but can't see where it says that streaming services are not allowed.

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.