Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    openvpn client not connecting

    Scheduled Pinned Locked Moved OpenVPN
    45 Posts 3 Posters 4.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      Cleetus Antony @Gertjan
      last edited by

      @Gertjan

      Thank you for the well explained reply. Appreciate it.

      For some reason, my ISP router doesnt have the port forwarding explicitly for ports only(1194 to 1194). IP fields are mandatory so I am not getting any to any option.

      @viragomann
      For setting the destination as WAN IP of ISP RTR, the same is on ppoe which changes more often rt ?

      GertjanG V 2 Replies Last reply Reply Quote 0
      • GertjanG
        Gertjan @Cleetus Antony
        last edited by Gertjan

        @Cleetus-Antony said in openvpn client not connecting:

        doesnt have the port forwarding explicitly for ports only(1194 to 1194). IP fields are mandatory so I am not getting any to any option

        "Only ports" can't exist.
        After all, a 'any' IP to 'any' IP doesn't make sense.

        It's nearly always "from any Internet IP possible" (as you don't know what IP you will be using when your out there using some random IPv4 (so = "any")) but the redirection has to go to a known IP : the pfSense WAN IP - and not some other "random LAN IP" (where LAN IP is an IP on your ISP LAN network, pfSense is using one of them, 192.168.10.10 - redirecting to for example 192.168.10.11 doesn't make sense, it has to be 192.168.10.10)

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • V
          viragomann @Cleetus Antony
          last edited by

          @Cleetus-Antony said in openvpn client not connecting:

          For setting the destination as WAN IP of ISP RTR, the same is on ppoe which changes more often rt ?

          There should be an alias for the random WAN IP, I think.

          I noted, that your router has a DMZ option. Maybe it also works if you state the pfSense WAN IP as DMZ.
          Normally this should forward any incoming traffic then.

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @viragomann
            last edited by Gertjan

            @viragomann said in openvpn client not connecting:

            Normally this should forward any incoming traffic then.

            ๐Ÿ‘

            @Cleetus-Antony
            This implies that you need a 'good' firewall after your ISP device ^^
            And that's the case : you use a pfSense ๐Ÿ˜Š

            I tend to see the "DMZ" often present in ISP boxes as a "no-brains super NAT rule" : Address Translate all in coming connection (ICMP, UDP, TCP, whatever) to the designated IP, which will be the pfSense WAN IP.
            This will surely do the trick.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            C 1 Reply Last reply Reply Quote 0
            • C
              Cleetus Antony @Gertjan
              last edited by Cleetus Antony

              @Gertjan

              Does all this means that my ISP router is not functioning well in terms of port forwarding to reach the openvpn traffic to pfsense. ? Do I need a replacement ? My current brand is GX Earth-4222 Router

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @Cleetus Antony
                last edited by

                @Cleetus-Antony
                This rather means, that setting a pfSense as DMZ on the ISP router is the common way to configure it, when you intend to run services in your network.

                This forward all incoming traffic to pfSense and you can control it there, which gives you better and more options.

                C 1 Reply Last reply Reply Quote 0
                • C
                  Cleetus Antony @viragomann
                  last edited by

                  @viragomann
                  I configured the DMZ section of the ISP router with the destination of WAN IP of the pfsense and it didnt make any difference.

                  V GertjanG 2 Replies Last reply Reply Quote 0
                  • V
                    viragomann @Cleetus Antony
                    last edited by

                    @Cleetus-Antony
                    If the WAN rule on pfSense doesn't show any hit there is obviously nothing forwarded.
                    So most probably the problem is in front of pfSense and there is not much we can help you.

                    Does the router provide diagnostic tools or logs to help investigating to issue?
                    Maybe you can sniff the traffic on its WAN to see, if there are even OpenVPN packets arriving.

                    1 Reply Last reply Reply Quote 0
                    • GertjanG
                      Gertjan @Cleetus Antony
                      last edited by Gertjan

                      @Cleetus-Antony said in openvpn client not connecting:

                      I configured the DMZ section of the ISP router with the destination of WAN IP of the pfsense and it didnt make any difference.

                      To possible test : ping.

                      get and note your WAN ISP IP.
                      Get a phone app that can send out pings (remember to switch of Wifi !! No VPN activated neither !!). Or go to to your neighbor.
                      Ping your WAN ISP IP.

                      Before you start pinging, set up a WAN ping sniffer :

                      56f78b1e-9ad1-46e8-8279-c7153ff5267e-image.png

                      and hit Start at the bottom.

                      If all goes well, you'll see lines like this :

                      df9506d4-7196-41e7-9862-59eaf17b0a60-image.png

                      Nothing comes in ?
                      That means nothing reached the WAN interface.

                      @Cleetus-Antony said in openvpn client not connecting:

                      Does all this means that my ISP router is not functioning well in terms of port forwarding to reach the openvpn traffic to pfsense. ? Do I need a replacement ? My current brand is GX Earth-4222 Router

                      Your ISP router image shows me all the needed for a port forward (NAT or/and PAT)

                      28bedfdd-c611-4c66-b947-358b2fa94659-image.png

                      What you need : go visit the ISP FAQ and documents about your router : how to implement a NAT or port forward rule.
                      Putting a VPN port forward in place is since 2019 considered 'common knowledge' and I really believe your router is capable of doing that.

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      C 1 Reply Last reply Reply Quote 0
                      • C
                        Cleetus Antony @Gertjan
                        last edited by

                        @Gertjan
                        Will try and update

                        GertjanG 1 Reply Last reply Reply Quote 0
                        • GertjanG
                          Gertjan @Cleetus Antony
                          last edited by

                          @Cleetus-Antony

                          Like : router GX Earth-4222 port forward ?!

                          If like the funny accent : a movie for you https://youtu.be/ZsfrGELbJbs?si=OTupRFVoPNNkrK5J

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          C 1 Reply Last reply Reply Quote 0
                          • C
                            Cleetus Antony @Gertjan
                            last edited by

                            @Gertjan

                            I can see hits now in openVPN for WAN interface. But not connecting.
                            Attached the logs. Please have a look.

                            1ef76965-c1b1-43f2-a255-861f7ef304c9-image.png

                            d769181b-67fa-47ab-bf40-09ec5d424379-image.png

                            d8ce9acf-baf3-469b-b1bf-d430f2f89f0e-image.png

                            GertjanG 1 Reply Last reply Reply Quote 0
                            • GertjanG
                              Gertjan @Cleetus Antony
                              last edited by

                              @Cleetus-Antony

                              Ok, progress !
                              Connections attempts are coming in now.

                              Question : one of these is the IP you were using with your client OpenVPN device :

                              f3e47169-6af2-45a2-839d-c92e3b39bb70-image.png

                              ?

                              No "help me" PM's please. Use the forum, the community will thank you.
                              Edit : and where are the logs ??

                              C 1 Reply Last reply Reply Quote 0
                              • C
                                Cleetus Antony @Gertjan
                                last edited by

                                @Gertjan
                                infact, I do try from my office PC thru office wifi only. My IP is different than the listed ones. I wonder how this IPs r showing as origin.

                                GertjanG 1 Reply Last reply Reply Quote 0
                                • GertjanG
                                  Gertjan @Cleetus Antony
                                  last edited by

                                  @Cleetus-Antony said in openvpn client not connecting:

                                  I wonder how this IPs r showing as origin.

                                  You are aware that every Internet device can access any IP ?
                                  You can go wherever you want, so can everybody else.
                                  What you are seeing are 'random' IP addresses that 'try' to connect to you WAN IP, protocol UDP, port 1194. They 'test' your OpenVPN.
                                  This looks scary if you've never seen this before, but don't worry, OpenVPN was created to handle this situation. You are probably using certificates as an access control mechanism :

                                  e840124b-2b44-42dd-b4c1-ffa080ce3c8b-image.png

                                  you can see these certificates - you saw them in the ovpn file you've exported to your client - and it's impossible to guess these.

                                  You Office PC is a PC that uses the Internet to go to you OpenVPN? right ?
                                  This Office PC should not be part of your pfSense LAN network.

                                  Normally, to test, you install this app on your phone (an iOS also exist) and you use your phone with the Wifi de activated. Use the data of your phone provider to connect to your ISP WAN IP.
                                  You know it works, as connections are already reaching your OpenVPN server ^^

                                  No "help me" PM's please. Use the forum, the community will thank you.
                                  Edit : and where are the logs ??

                                  C 2 Replies Last reply Reply Quote 0
                                  • C
                                    Cleetus Antony @Gertjan
                                    last edited by

                                    @Gertjan

                                    Ya I thought that "may" be some attack attempts. BUT:-
                                    I am in UAE now and my home is in India where pfsense is located.
                                    My home IP is 59.88.4.40
                                    but openvpn client from my office pc is trying to connect to 117.196.173.241:1194.

                                    I am using dyndns at my pfsense end. As per my research this ip 117.196.173.241 doesnt belong to my dyndns.

                                    This makes me kind of total confusions.

                                    I tried both User auth as well as TLS modes.

                                    Attached the latest openvpn log from pfsense. Plz chk if u can see anything interesting ?

                                    openvpnLog 18.11.24.txt

                                    3567444a-e2e0-453a-8c68-dc35f01165a3-image.png

                                    785c0a00-4146-4095-abea-434c33b955f6-image.png

                                    bf99a584-4d0f-4e04-b06c-2596e5f1fca8-image.png

                                    GertjanG 1 Reply Last reply Reply Quote 0
                                    • GertjanG
                                      Gertjan @Cleetus Antony
                                      last edited by Gertjan

                                      @Cleetus-Antony said in openvpn client not connecting:

                                      My home IP is 59.88.4.xx
                                      but openvpn client from my office pc is trying to connect to 117.196.173.241:1194.

                                      That makes no sense.
                                      If you know your that the IP you need to contact is is 59.88.4.xx then why would you (have it) use 117.196.a.b ?
                                      DynDNS issues ? Who cares. Handle that one later.
                                      For now, set up the IP like :

                                      85effcbf-0c0c-4d1a-b1d7-df75613ed0d9-image.png

                                      export the Client OpenVPN config.
                                      Import the config in the client.

                                      @Cleetus-Antony said in openvpn client not connecting:

                                      I tried both User auth as well as TLS modes.

                                      Starting testing the user auth possibilities when you are able to reach 59.88.4.xx

                                      No "help me" PM's please. Use the forum, the community will thank you.
                                      Edit : and where are the logs ??

                                      1 Reply Last reply Reply Quote 0
                                      • C
                                        Cleetus Antony @Gertjan
                                        last edited by

                                        @Gertjan
                                        Sorry that I couldn't respond to u after the last talk.

                                        I managed connect the opnvpn from my work place to home pfsense server.
                                        But I my open vpn adaptor is not getting gateway and dns.

                                        Please revert.

                                        05bcc778-cfd9-42a1-8aa8-48c9aa1825be-image.png

                                        GertjanG 1 Reply Last reply Reply Quote 0
                                        • GertjanG
                                          Gertjan @Cleetus Antony
                                          last edited by

                                          @Cleetus-Antony

                                          254600e5-f4bc-466a-a88e-024ada7e3bb6-image.png

                                          Really, TAP ?

                                          No "help me" PM's please. Use the forum, the community will thank you.
                                          Edit : and where are the logs ??

                                          C 2 Replies Last reply Reply Quote 0
                                          • C
                                            Cleetus Antony @Gertjan
                                            last edited by

                                            @Gertjan

                                            Yes sir, Thats what the adaptor is getting my tunnel network IP from 192.168.2.0 series when connected.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.