Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN client assistance

    Scheduled Pinned Locked Moved OpenVPN
    31 Posts 3 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Antibiotic
      last edited by

      Please assist me with client settings. OpenVPN connected fine to remote server but do not have vpn traffic locally:
      Floatingrules.jpeg Lanrules.jpeg Openvpn.jpeg VPN.jpeg NAT.jpeg Status.jpeg Resolver.jpeg Screenshot_4-4-2024_19410_192.168.10.1.jpeg Screenshot_4-4-2024_19440_192.168.10.1.jpeg
      What is wrong in mt settings?

      pfSense plus 24.11 on Topton mini PC
      CPU: Intel N100
      NIC: Intel i-226v 4 pcs
      RAM : 16 GB DDR5
      Disk: 128 GB NVMe
      Brgds, Archi

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @Antibiotic
        last edited by

        @Antibiotic said in OpenVPN client assistance:

        OpenVPN connected fine to remote server but do not have vpn traffic locally:

        Many screenshots, but view information. Can you give more details on your problem?

        A 1 Reply Last reply Reply Quote 0
        • A
          Antibiotic @viragomann
          last edited by Antibiotic

          @viragomann If trying to get traffic over VPN for WIFI ethernet (192.168.10.0/24)with this settings , my interface in this case WIFI don't have internet access! I want that only WIFI go over VPN tunnel. WIFI router connected to pfSense in AP wireless mode/

          pfSense plus 24.11 on Topton mini PC
          CPU: Intel N100
          NIC: Intel i-226v 4 pcs
          RAM : 16 GB DDR5
          Disk: 128 GB NVMe
          Brgds, Archi

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @Antibiotic
            last edited by

            @Antibiotic
            Is it really in AP mode now? In your other thread you had it in router mode.

            I guess, the VPN is an upstream provider, allowing you to hide your IP?

            The policy routing rule on the wifi interface shows some states and some kB. So I assume, it routed some traffic to the VPN gateway.
            To rule out a DNS issue, try to ping an IP in the internet, e.g. 1.1.1.1.

            BTW: If your wifi devices use the local DNS Resolver and internet access is routed out over the VPN, you will run into DNS leaks.
            The easiest way to circumvent this is to forward DNS request from the wifi to any server over the VPN, could be the DNS of the VPN provider or any other public DNS server.
            However, this bypasses the Resolver and local host names cannot be resolved then.

            A 1 Reply Last reply Reply Quote 0
            • A
              Antibiotic @viragomann
              last edited by Antibiotic

              @viragomann

              1. Yes router in AP mode
              2. With VPN tunnel on WIFI ping is going, no any packets lost, but internet do not have!
              3. Regarding DNS leakage understood, but not important for me, me only want to secure wifi traffic with encryption and hide internet browsing from ISP. I know they will see my DNS request, where me go but the rest traffic will encrypted anyway. But where is my mistake now with settings do not understand? I want that pfBlockerNG to see DNS request to filter VPN traffic
              4. Yes, the VPN is an upstream provider.
                AsusRouter.jpeg
                AsusLAN.jpeg

              pfSense plus 24.11 on Topton mini PC
              CPU: Intel N100
              NIC: Intel i-226v 4 pcs
              RAM : 16 GB DDR5
              Disk: 128 GB NVMe
              Brgds, Archi

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @Antibiotic
                last edited by

                @Antibiotic said in OpenVPN client assistance:

                Yes router in AP mode

                So your wifi devices get IPs in 192.168.10.0/24 from pfSense and hence also get the DNS server?

                With VPN tunnel on WIFI ping is going, no any packets lost, but internet do not have!

                You mean to an IP like 8.8.8.8, but not to google.com?
                So the wifi devices probably cannot resolve host names.
                Try to investigate this with dig or nslookup on a device. What do you get?

                A 2 Replies Last reply Reply Quote 0
                • A
                  Antibiotic @viragomann
                  last edited by

                  @viragomann So your wifi devices get IPs in 192.168.10.0/24 from pfSense and hence also get the DNS server? YES
                  Screenshot_4-4-2024_213437_192.168.10.1.jpeg Screenshot_4-4-2024_213342_192.168.10.1.jpeg Screenshot_4-4-2024_21337_192.168.10.1.jpeg

                  [2.7.2-RELEASE][admin@pfSense.home.arpa]/root: dig google.com

                  ; <<>> DiG 9.18.19 <<>> google.com
                  ;; global options: +cmd
                  ;; Got answer:
                  ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 43895
                  ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

                  ;; OPT PSEUDOSECTION:
                  ; EDNS: version: 0, flags:; udp: 1432
                  ;; QUESTION SECTION:
                  ;google.com. IN A

                  ;; ANSWER SECTION:
                  google.com. 300 IN A 172.217.21.174

                  ;; Query time: 26 msec
                  ;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP)
                  ;; WHEN: Thu Apr 04 21:37:15 EEST 2024
                  ;; MSG SIZE rcvd: 55

                  pfSense plus 24.11 on Topton mini PC
                  CPU: Intel N100
                  NIC: Intel i-226v 4 pcs
                  RAM : 16 GB DDR5
                  Disk: 128 GB NVMe
                  Brgds, Archi

                  V 1 Reply Last reply Reply Quote 0
                  • A
                    Antibiotic @viragomann
                    last edited by

                    @viragomann I have port restrictions for this interface, do not know this could be a problem or not?
                    Screenshot_4-4-2024_214555_192.168.10.1.jpeg Screenshot_4-4-2024_214410_192.168.10.1.jpeg

                    pfSense plus 24.11 on Topton mini PC
                    CPU: Intel N100
                    NIC: Intel i-226v 4 pcs
                    RAM : 16 GB DDR5
                    Disk: 128 GB NVMe
                    Brgds, Archi

                    1 Reply Last reply Reply Quote 0
                    • V
                      viragomann @Antibiotic
                      last edited by

                      @Antibiotic
                      I'm not in doubt, that pfSense can resolve host names well, to be honest. The point is, what you get on a wifi-connected device.

                      A 1 Reply Last reply Reply Quote 0
                      • A
                        Antibiotic @viragomann
                        last edited by

                        @viragomann said in OpenVPN client assistance:

                        The point is, what you get on a wifi-connected device

                        What do you mean?

                        pfSense plus 24.11 on Topton mini PC
                        CPU: Intel N100
                        NIC: Intel i-226v 4 pcs
                        RAM : 16 GB DDR5
                        Disk: 128 GB NVMe
                        Brgds, Archi

                        V 1 Reply Last reply Reply Quote 0
                        • V
                          viragomann @Antibiotic
                          last edited by

                          @Antibiotic
                          Connect a laptop to the wifi and run nslookup or dig against a public host name on it.

                          A 1 Reply Last reply Reply Quote 0
                          • A
                            Antibiotic @viragomann
                            last edited by

                            @viragomann Ah ok , this is a result from WIFI router:
                            Screenshot_4-4-2024_215842_192.168.10.10.jpeg Screenshot_4-4-2024_215751_192.168.10.10.jpeg Screenshot_4-4-2024_21576_192.168.10.10.jpeg

                            pfSense plus 24.11 on Topton mini PC
                            CPU: Intel N100
                            NIC: Intel i-226v 4 pcs
                            RAM : 16 GB DDR5
                            Disk: 128 GB NVMe
                            Brgds, Archi

                            V 1 Reply Last reply Reply Quote 0
                            • V
                              viragomann @Antibiotic
                              last edited by viragomann

                              @Antibiotic
                              Can you show the interface configuration of this device, please?

                              DNS resolution works so far obviously.

                              A 2 Replies Last reply Reply Quote 0
                              • A
                                Antibiotic @viragomann
                                last edited by

                                @viragomann Do you mean LAN settings of WIFI router?

                                pfSense plus 24.11 on Topton mini PC
                                CPU: Intel N100
                                NIC: Intel i-226v 4 pcs
                                RAM : 16 GB DDR5
                                Disk: 128 GB NVMe
                                Brgds, Archi

                                V 1 Reply Last reply Reply Quote 0
                                • V
                                  viragomann @Antibiotic
                                  last edited by

                                  @Antibiotic
                                  This is the wifi router?
                                  Then the test is useless. You need to check this from a device, which is connected to the wireless. This is, where you have troubles, so this case has to be investigated.

                                  A 1 Reply Last reply Reply Quote 0
                                  • A
                                    Antibiotic @viragomann
                                    last edited by

                                    @viragomann From Laptop connected to WIFI router result:
                                    PS C:\Users\archi> nslookup google.com
                                    Server: pfSense.home.arpa
                                    Address: 192.168.10.1

                                    Non-authoritative answer:
                                    Name: google.com
                                    Addresses: 2a00:1450:400f:80a::200e
                                    172.217.21.174

                                    PS C:\Users\archi> nslookup 8.8.8.8
                                    Server: pfSense.home.arpa
                                    Address: 192.168.10.1

                                    Name: dns.google
                                    Address: 8.8.8.8

                                    PS C:\Users\archi>

                                    pfSense plus 24.11 on Topton mini PC
                                    CPU: Intel N100
                                    NIC: Intel i-226v 4 pcs
                                    RAM : 16 GB DDR5
                                    Disk: 128 GB NVMe
                                    Brgds, Archi

                                    1 Reply Last reply Reply Quote 0
                                    • A
                                      Antibiotic @viragomann
                                      last edited by Antibiotic

                                      @viragomann Laptop settings:
                                      Screenshot 2024-04-04 222711.png

                                      pfSense plus 24.11 on Topton mini PC
                                      CPU: Intel N100
                                      NIC: Intel i-226v 4 pcs
                                      RAM : 16 GB DDR5
                                      Disk: 128 GB NVMe
                                      Brgds, Archi

                                      V 1 Reply Last reply Reply Quote 0
                                      • V
                                        viragomann @Antibiotic
                                        last edited by

                                        @Antibiotic
                                        So everything seems fine on your site.

                                        Now I have to ask again after 17 posts, what is the real problem??
                                        Which kind of connection does not work?
                                        What output do you get? Error message or whatever?

                                        A 2 Replies Last reply Reply Quote 0
                                        • A
                                          Antibiotic @viragomann
                                          last edited by

                                          @viragomann Sorry my friend, after 2 days of fighting with VPN, removed all. Could be next time try again but now my nervous system is become too weak))))) Anyway thanks a lot to try assist me and spent your time.

                                          pfSense plus 24.11 on Topton mini PC
                                          CPU: Intel N100
                                          NIC: Intel i-226v 4 pcs
                                          RAM : 16 GB DDR5
                                          Disk: 128 GB NVMe
                                          Brgds, Archi

                                          GertjanG 1 Reply Last reply Reply Quote 0
                                          • GertjanG
                                            Gertjan @Antibiotic
                                            last edited by Gertjan

                                            @Antibiotic said in OpenVPN client assistance:

                                            but now my nervous system

                                            Check this one - the whole story.

                                            Now I write down what I think :

                                            DNS is worth $$$
                                            And who has access to : Your real IP and your DNS data ? and keep in mind that combination of the two make the data even more valuable ?
                                            Right.
                                            I thinks these *****VPN supplier really start to think lately about how to make the max out of it.
                                            And thinks get even better : you pay them .... or, when you read the thread above, one might ask : why don't they pay me ? or you ?

                                            Why would they do all this ?
                                            Simple. if I or you were working for them, I (we) would do exactly that : DNS interception.

                                            Again, me just thinking, right ^^

                                            No "help me" PM's please. Use the forum, the community will thank you.
                                            Edit : and where are the logs ??

                                            A 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.