Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can pfsense do this (newbie)?

    OpenVPN
    2
    3
    2.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      iulian_2007
      last edited by

      Hello,

      I'm looking for a good vpn server and I came across pfsense. Here is what I want to do: I need a VPN server with 1 external interface (public IP for clients to connect) and 3 internal interfaces (different networks). I want the clients to connect to the VPN server and based on username or certificate to get into network A, B or C. Can pfsense do this??

      Thank you

      1 Reply Last reply Reply Quote 0
      • I
        iulian_2007
        last edited by

        more info:
        external interface: a.b.c.d (public IP)
        internal interface LAN1: 192.168.1.x
        internal interface LAN2: 10.10.10.x
        internal interface LAN3: 172.16.1.x

        and based on username or certificate to get ip from LAN1,2 or 3

        also, is it possible to integrate it with active directory? I mean to login to VPN using active directory username and password…

        1 Reply Last reply Reply Quote 0
        • GruensFroeschliG
          GruensFroeschli
          last edited by

          Yes this is possible with the "Client-specific configuration" (client specific pushes)
          and with OpenVPN firewall rules. (Although the firewalling of OpenVPN is currently quite a hack).

          But you missunderstand that you get an IP out of your 3 subnets. This wont happen. You connect from a different subnet to these private LANs.

          Yes you can integrate this with active directory.
          Read the stickies !
          http://forum.pfsense.org/index.php/topic,14946.0.html

          We do what we must, because we can.

          Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.