Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN does not work on bridged PFsense router

    Scheduled Pinned Locked Moved OpenVPN
    71 Posts 3 Posters 10.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JonathanLeeJ
      JonathanLee @george1116
      last edited by JonathanLee

      @george1116

      If it’s behind your home router did you port forward port 1194 to it from your home router? It needs to know where to send that traffic.

      Make sure to upvote

      G 1 Reply Last reply Reply Quote 0
      • G
        george1116 @JonathanLee
        last edited by george1116

        @JonathanLee The router LAN port is in already in bridged mode, so I didn't forward that 1194 port. Do I still need to?

        1 Reply Last reply Reply Quote 0
        • JonathanLeeJ
          JonathanLee
          last edited by JonathanLee

          O ok, can you capture traffic and generate a PCP file from inside PFsense and attempt the connection again? PFsense can do that for you to help isolate the issue. We want to grab the pcap file and import it into Wireshark so we can look at what occurs. We want to see that port hit PFsense and when it drops.

          Make sure to upvote

          G 1 Reply Last reply Reply Quote 0
          • G
            george1116 @JonathanLee
            last edited by

            @JonathanLee You want me to share the Packet capture file?

            JonathanLeeJ 1 Reply Last reply Reply Quote 0
            • JonathanLeeJ
              JonathanLee @george1116
              last edited by JonathanLee

              @george1116 no because it could have info you don’t want shared. just open it with wireshark search for that port number do a screenshot of just that and post it here, I just want to see that connect initiated not the details of it.

              Make sure to upvote

              G 1 Reply Last reply Reply Quote 0
              • G
                george1116 @JonathanLee
                last edited by

                @JonathanLee Screenshot 2024-01-03 at 9.00.05 AM.png

                JonathanLeeJ 1 Reply Last reply Reply Quote 0
                • JonathanLeeJ
                  JonathanLee @george1116
                  last edited by

                  @george1116

                  That's good it hits your firewall, it looks to be a certificate issue here, can you delete the client info and export it again?

                  How are you accessing the VPN?

                  Make sure to upvote

                  G 1 Reply Last reply Reply Quote 0
                  • G
                    george1116 @JonathanLee
                    last edited by george1116

                    @JonathanLee

                    I am using Tunnelblick to connect.

                    How is it able to connect on a mobile network though if it's indeed a problem with the certificate?

                    Also, which client info are you referring to?

                    JonathanLeeJ 2 Replies Last reply Reply Quote 0
                    • JonathanLeeJ
                      JonathanLee @george1116
                      last edited by

                      @george1116 What is your goal? RDM? Access a NAS?

                      Make sure to upvote

                      G 1 Reply Last reply Reply Quote 0
                      • G
                        george1116 @JonathanLee
                        last edited by george1116

                        @JonathanLee Purely RDM, I want to be able to manage my network from other locations.

                        JonathanLeeJ 2 Replies Last reply Reply Quote 0
                        • JonathanLeeJ
                          JonathanLee @george1116
                          last edited by JonathanLee

                          @george1116 You have different export wizards in OpenVPN for different machines. Also if you open that file in a text editor you may see udp4 if you have a ipv6 hotspot it will need that disabled change it to udp only.

                          251d8d8f-55bd-40b7-a13d-eab2da2edaf7-image.png

                          Export and try this also change to just udp, I had an issue that was not letting my use my iphone yesterday when it was set to udp4 because the iphone could not understand that it just wanted it set to udp

                          09d26118-4902-4caa-9484-f01b4e094bdf-image.png

                          remote f.q.d.n (your ip address will show here) 1194 udp

                          not
                          remote f.q.d.n (your ip address here) 1194 udp4

                          Make sure to upvote

                          1 Reply Last reply Reply Quote 0
                          • JonathanLeeJ
                            JonathanLee @george1116
                            last edited by JonathanLee

                            @george1116 That is good it works already so we know it's mostly some setting in the client export profile file.

                            Are you using pfsense for OpenVPN? if not you need to set it to forward the traffic to the device that has the vpn software set up on.

                            If you only use VPN software on the mac pfsense needs to reroute that port to that machine

                            You might need to NAT port foward port 1194 to that machine if that is where your VPN software is located.

                            Here is an example I use port forward for my AP for syslogs to pfsense so ap 192.168.1.2:514 ----> 192.168.1.1:5140

                            d206826b-a03f-4373-9673-e7ff77e39388-image.png

                            Make sure to upvote

                            G 1 Reply Last reply Reply Quote 0
                            • JonathanLeeJ
                              JonathanLee @george1116
                              last edited by

                              @george1116 is OpenVPN used in pfSense or just VPN software on the mac is uses and pfSense does not have VPN software installed on it?

                              Make sure to upvote

                              1 Reply Last reply Reply Quote 0
                              • G
                                george1116 @JonathanLee
                                last edited by george1116

                                @JonathanLee

                                yes, I am using pfsense for OpenVPN. By default, it accepts all UDP connections on the WAN port.

                                Also, this is what part of my config file looks like, it is already setup like yours.

                                Screenshot 2024-01-03 at 9.37.11 AM.png

                                JonathanLeeJ 1 Reply Last reply Reply Quote 0
                                • JonathanLeeJ
                                  JonathanLee @george1116
                                  last edited by

                                  @george1116 change it to just udp and save it import it and try again

                                  Make sure to upvote

                                  G 1 Reply Last reply Reply Quote 0
                                  • G
                                    george1116 @JonathanLee
                                    last edited by

                                    @JonathanLee

                                    Please help me understand, what am I changing to UDP only. it's already set to only use UDP, so I am a little confused right now.

                                    JonathanLeeJ 1 Reply Last reply Reply Quote 0
                                    • JonathanLeeJ
                                      JonathanLee @george1116
                                      last edited by

                                      @george1116 it says udp4 that is upd ipv4 some systems cannot understand it like my iphone it just wants it to say udp.

                                      Make sure to upvote

                                      G 1 Reply Last reply Reply Quote 1
                                      • G
                                        george1116 @JonathanLee
                                        last edited by george1116

                                        @JonathanLee

                                        Modified and it didn't work either 😧

                                        still failing at

                                        2024-01-03 09:53:25.497694 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
                                        2024-01-03 09:53:25.497766 TLS Error: TLS handshake failed
                                        
                                        V JonathanLeeJ 2 Replies Last reply Reply Quote 0
                                        • V
                                          viragomann @george1116
                                          last edited by

                                          @george1116
                                          What shows the server log?

                                          G 1 Reply Last reply Reply Quote 0
                                          • JonathanLeeJ
                                            JonathanLee @george1116
                                            last edited by

                                            @george1116 dang

                                            Make sure to upvote

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.