Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN client

    Scheduled Pinned Locked Moved OpenVPN
    25 Posts 3 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Antibiotic @viragomann
      last edited by Antibiotic

      @viragomann The purpose to make all home network going over this client. All PC's in LAN network to use this VPN client on pfsense before touch internet.

      pfSense plus 24.11 on Topton mini PC
      CPU: Intel N100
      NIC: Intel i-226v 4 pcs
      RAM : 16 GB DDR5
      Disk: 128 GB NVMe
      Brgds, Archi

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @Antibiotic
        last edited by

        @antibiotic
        So I assume, you connect to a VPN provider.
        There is no special VPN gateway for this if the provider normally pushes default route to you, which is default behavior. Anyway, if it's already configured, you can leave it.

        But did you set the outbound NAT into the hybrid mode add a rule to the OpenVPN interface?

        A 1 Reply Last reply Reply Quote 0
        • A
          Antibiotic @viragomann
          last edited by Antibiotic

          @viragomann Negative sir, any tutorial? I see in NAT hybrid mode but what kind of rule should add? Should I'm transfer to hybrid mode and save it?

          pfSense plus 24.11 on Topton mini PC
          CPU: Intel N100
          NIC: Intel i-226v 4 pcs
          RAM : 16 GB DDR5
          Disk: 128 GB NVMe
          Brgds, Archi

          S V 2 Replies Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @Antibiotic
            last edited by

            @antibiotic check out https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-s2s-route-internet-traffic.html I think it’s closer to what you’re looking for.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote 👍 helpful posts!

            1 Reply Last reply Reply Quote 0
            • V
              viragomann @Antibiotic
              last edited by

              @antibiotic said in VPN client:

              Negative sir, any tutorial?

              You should ask this you VPN provider. Normally he should provide set up tutorials for certain clients.

              Yes, an outbound NAT is needed. If you want to get details here, please come with your related settings first.

              A 1 Reply Last reply Reply Quote 0
              • A
                Antibiotic @viragomann
                last edited by

                @viragomann My settings here but not working :
                Screenshot 2023-03-24 153529.png Screenshot 2023-03-24 153601.png Screenshot 2023-03-24 153624.png

                pfSense plus 24.11 on Topton mini PC
                CPU: Intel N100
                NIC: Intel i-226v 4 pcs
                RAM : 16 GB DDR5
                Disk: 128 GB NVMe
                Brgds, Archi

                V 1 Reply Last reply Reply Quote 0
                • V
                  viragomann @Antibiotic
                  last edited by

                  @antibiotic
                  This outbound NAT rule covers only access from pfSense itself. You need also one for your local network.

                  So copy it by clicking the button at the right and change the source in the new rule to your LAN network 192.168.10.0/24.

                  A 1 Reply Last reply Reply Quote 0
                  • A
                    Antibiotic @viragomann
                    last edited by

                    @viragomann did but not workingScreenshot 2023-03-24 154721.png

                    pfSense plus 24.11 on Topton mini PC
                    CPU: Intel N100
                    NIC: Intel i-226v 4 pcs
                    RAM : 16 GB DDR5
                    Disk: 128 GB NVMe
                    Brgds, Archi

                    V 1 Reply Last reply Reply Quote 0
                    • V
                      viragomann @Antibiotic
                      last edited by

                      @antibiotic said in VPN client:

                      did but not working

                      What does this mean?
                      No access to the internet?
                      Wrong WAN IP?

                      Please give details!

                      A 1 Reply Last reply Reply Quote 0
                      • A
                        Antibiotic @viragomann
                        last edited by Antibiotic

                        @viragomann I have internet but , IP checking show me my real IP address not a VPN address.Screenshot 2023-03-24 155640.png

                        pfSense plus 24.11 on Topton mini PC
                        CPU: Intel N100
                        NIC: Intel i-226v 4 pcs
                        RAM : 16 GB DDR5
                        Disk: 128 GB NVMe
                        Brgds, Archi

                        V 1 Reply Last reply Reply Quote 0
                        • V
                          viragomann @Antibiotic
                          last edited by

                          @antibiotic
                          Please post Status > Gateways.
                          You may hide your WAN gw.

                          A 1 Reply Last reply Reply Quote 0
                          • A
                            Antibiotic @viragomann
                            last edited by

                            @viragomann Screenshot 2023-03-24 160209.png

                            pfSense plus 24.11 on Topton mini PC
                            CPU: Intel N100
                            NIC: Intel i-226v 4 pcs
                            RAM : 16 GB DDR5
                            Disk: 128 GB NVMe
                            Brgds, Archi

                            V 1 Reply Last reply Reply Quote 0
                            • V
                              viragomann @Antibiotic
                              last edited by

                              @antibiotic
                              Well, the VPN gateway is not the default gateway. I assume, the connection is established, so there must be something wrong in the VPN client settings.
                              Can you post the "Tunnel Settings" section, please?

                              A 1 Reply Last reply Reply Quote 0
                              • A
                                Antibiotic @viragomann
                                last edited by

                                @viragomann Screenshot 2023-03-24 161325.png Screenshot 2023-03-24 161341.png Screenshot 2023-03-24 161354.png

                                pfSense plus 24.11 on Topton mini PC
                                CPU: Intel N100
                                NIC: Intel i-226v 4 pcs
                                RAM : 16 GB DDR5
                                Disk: 128 GB NVMe
                                Brgds, Archi

                                V 1 Reply Last reply Reply Quote 0
                                • V
                                  viragomann @Antibiotic
                                  last edited by

                                  @antibiotic
                                  Remove the check at "Don't pull routes". It prohibits that the client can set the default route to the VPN provider.

                                  A 1 Reply Last reply Reply Quote 0
                                  • A
                                    Antibiotic @viragomann
                                    last edited by Antibiotic

                                    @viragomann Ops now start working))) Thanks you for assistance. But default gateway still my ISP provider( Status gateway), is it normally? Second question can I use squid proxy with VPN client for caching web or will not any profit or will not work? Should I remove in firewall LAN settings rule (Default allow LAN IPv4 to any rule)

                                    pfSense plus 24.11 on Topton mini PC
                                    CPU: Intel N100
                                    NIC: Intel i-226v 4 pcs
                                    RAM : 16 GB DDR5
                                    Disk: 128 GB NVMe
                                    Brgds, Archi

                                    V 1 Reply Last reply Reply Quote 0
                                    • V
                                      viragomann @Antibiotic
                                      last edited by

                                      @antibiotic said in VPN client:

                                      But default gateway still my ISP provider( Status gateway), is it normally?

                                      I think so. As far as I know, the default route is splited into two parts from OpenVPN, 0.0.0.0/1 and 128.0.0.0/1. So it's not determined as default route by pfSense.

                                      See Diagnostic > routes

                                      Second question can I use squid proxy with VPN client for caching web or will not any profit or will not work?

                                      I don't use squid, so don't know. But I think, why not, it should be doable.

                                      A 1 Reply Last reply Reply Quote 0
                                      • A
                                        Antibiotic @viragomann
                                        last edited by

                                        @viragomann Should I remove in firewall LAN settings rule (Default allow LAN IPv4 to any rule)

                                        pfSense plus 24.11 on Topton mini PC
                                        CPU: Intel N100
                                        NIC: Intel i-226v 4 pcs
                                        RAM : 16 GB DDR5
                                        Disk: 128 GB NVMe
                                        Brgds, Archi

                                        V 1 Reply Last reply Reply Quote 0
                                        • V
                                          viragomann @Antibiotic
                                          last edited by

                                          @antibiotic
                                          Don't know, whats the suppose of your "local subnets" alias.
                                          At the moment the default allow rule would pass any traffic with different source than "local subnets".

                                          A different source could be the case if you have a router within your local network like a VPN endpoint, which passes traffic trough.
                                          But where will it get to? Since you obviously have a single LAN subnet, which might be included in the local subnets alias, the traffic could be go to the WAN or VPN at its best, but would fail then, since it is not natted (Outbound NAT source).

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.