Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Need help setting up VPN for my laptop

    Scheduled Pinned Locked Moved OpenVPN
    9 Posts 3 Posters 2.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      Deadringers
      last edited by

      Hey all,

      Just a single VPN user (me) for my home network.

      Running PFsense and trying to get Open VPN working on the PFsense box with my laptop as the remote client.

      However I am struggling!
      I have tried to follow some guides but no sure what certain parts of them mean.

      Also I see no option to "start" the VPN.  I have the certs all on my laptop in the right folder and have created the .ovpn file but no idea how to "run" it?

      Can someone point me to a step by step guide to setting up a road warrior user which they used?

      Thanks

      1 Reply Last reply Reply Quote 0
      • S
        SeventhSon
        last edited by

        I used the OpenVPN Client Export package, works like a charm, just make sure you have a user setup for OpenVPN and set the "Host Name Resolution" to the right external IP/DNS name before you download the Windows Installer.

        (I'm assuming you're using Windows)

        1 Reply Last reply Reply Quote 0
        • D
          Deadringers
          last edited by

          Right!

          Thanks I have now followed this guide as best I can:
          http://hardforum.com/showthread.php?t=1663797&page=3

          and I have the VPN connected now.

          however I don't understand the VPN…I am connected and have an address but cannot access the LAN.
          The new network adapter which has been created also shows no internet connectivity.

          Any ideas guys.

          here is a screenshot of my config: - I thought I should put a range in which is not in the DHCP scope of my LAN as the tunnel network?

          config.PNG
          config.PNG_thumb

          1 Reply Last reply Reply Quote 0
          • D
            Deadringers
            last edited by

            hmm just noticed that the new vpn adapter doesn't have a default gateway..could be the reason why?!

            my server (2008r2) currently performs the dhcp and dns for the network at home.

            Does this affect how my clients can VPN in?

            1 Reply Last reply Reply Quote 0
            • S
              SeventhSon
              last edited by

              VPN subnet should be outside :LAN range, so try 192.168.123.0/24 or something.

              1 Reply Last reply Reply Quote 0
              • D
                Deadringers
                last edited by

                Right I tried it with .100.0/24 and it's still not giving me a default gateway?

                Capture.PNG
                Capture.PNG_thumb

                1 Reply Last reply Reply Quote 0
                • P
                  phil.davis
                  last edited by

                  You don't need a default route into the tunnel. The "Local Network" field on your server settings should cause the client to add a route through the tunnel to that subnet.
                  On the pfSense you need to add firewall rules on OpenVPN allowing whatever you want to allow from the client end - e.g. pass source any, destination LAN network - will allow traffic from the client end to anything on the LAN.

                  As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                  If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                  1 Reply Last reply Reply Quote 0
                  • D
                    Deadringers
                    last edited by

                    Thanks I have got this working now :)

                    Just wondering - a guide a followed suggested that I use DH 1024 and AES 128

                    Could i bump up the DH to 2048 with no issues?

                    1 Reply Last reply Reply Quote 0
                    • S
                      SeventhSon
                      last edited by

                      As long as you're using an OpenVPN that supports it. Some clients (on phones/tablets?) might not support it.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.