Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to create an OpenVPN client to StrongVPN

    Scheduled Pinned Locked Moved OpenVPN
    157 Posts 56 Posters 226.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tjabas
      last edited by

      i havent even tried yet to istall it, i have made the purchase and all but i read that strong vpn changed someting so the guide in this thread dont work anymore.

      or am i wrong?

      1 Reply Last reply Reply Quote 0
      • T
        tjabas
        last edited by

        is there anyone else that hasnt got the preconfigured file to work?
        i thought that if i only buy the file and istall the keys, it all would work, but i was wrong.

        1 Reply Last reply Reply Quote 0
        • E
          ericab
          last edited by

          @tjabas:

          is there anyone else that hasnt got the preconfigured file to work?
          i thought that if i only buy the file and istall the keys, it all would work, but i was wrong.

          what isnt working for you tjabas ? if you dont give us details on the problem we cant help you

          1 Reply Last reply Reply Quote 0
          • T
            tjabas
            last edited by

            the main issue is that i loose the wan Connection after i have installed the purchased backup file, the wan is still assigned to the same nic, and the router is acting really really slow, the webserver is almost useless, but what i have seen so isnt there any Changes to the wan and nic, there the same as Before but i dont get any ip from mi isp.

            any suggestions?

            1 Reply Last reply Reply Quote 0
            • R
              richardkingsley
              last edited by

              Hi,

              After a few misconfigurations, i have finally got a client to strongvpn working but for the whole lan subnet and not for the specific ip address that i want to route.

              I have tried setting a rule in the firewall>rules>lan section but it still seems to route everything to through the vpn.

              It seems that just having the manual outward NAT settings for the lan is enough to make everything route via vpn with no firewll rules

              Does anybody have any pointers where to check where i may be going wrong. I am using 2.1rc2

              Thanks

              Richard

              1 Reply Last reply Reply Quote 0
              • H
                hammerman
                last edited by

                as per ericab reply 21,
                if i have everything going through the vpn now and only want to route devices with specific ip addresses through the vpn, do i just follow the new firewall rule and save it? that's it?
                do i have to change any existing rules or move this new rule to the top?

                thanks

                1 Reply Last reply Reply Quote 0
                • H
                  hammerman
                  last edited by

                  i tried ericab's way and it didn't work.
                  my pc was still running through the vpn.
                  i only want specific ip addresses to use the vpn.
                  i must be missing something . . . .???

                  1 Reply Last reply Reply Quote 0
                  • H
                    hammerman
                    last edited by

                    BUMP !!!

                    somebody please offer some help here !

                    if i followed the setup and it works, meaning all traffic is going through the vpn, then how is ericab's solution (reply 21) supposed to work?
                    yu13096 wanted "only 1 specific internal IP with all the other IPs going through the default gateway."
                    yet ericab's solution is that all traffic goes through the vpn and then you force one address i.e. netflix to go through the same vpn???
                    shouldn't it be that all traffic goes through the default gateway and only the netflix address goes through the vpn?

                    clearly i'm missing something here and i would appreciate some help in setting it so that all traffic goes through the default gateway and individual addresses use the vpn . . . or all traffic goes through the vpn and individual addresses use the default. doesn't matter which one.

                    thank you.

                    1 Reply Last reply Reply Quote 0
                    • M
                      Meloman
                      last edited by

                      Hi,

                      I don't know if it could help, but after many time to try to get this functional, it is now OK.

                      I followed all this howto, except I changed "BF-CBC" to "AES-128-CBC" !

                      I'm on 2.1 and all is working, gateway is fine and my IP is US (instead of Switzerland)

                      ovpn-aes-128.png
                      ovpn-aes-128.png_thumb
                      ovpn-status.png
                      ovpn-status.png_thumb
                      ovpn-gw.png
                      ovpn-gw.png_thumb

                      1 Reply Last reply Reply Quote 0
                      • D
                        dalesd
                        last edited by

                        Thanks so much for this guide.

                        The VPN provider I'm using has instructions for running on pFsense, but this guide is much better. 
                        Their instructions got the VPN running, but no traffic was passing. This guide showed me the firewall rules I needed to get things really working.

                        Also, pfSense running on an old HP7900 SFF pc is easily handling my 50/25 Mb/s connection.  I gotta thank the hardware forum for that recommendation.

                        1 Reply Last reply Reply Quote 0
                        • T
                          tjabas
                          last edited by

                          @dalesd:

                          Thanks so much for this guide.

                          The VPN provider I'm using has instructions for running on pFsense, but this guide is much better. 
                          Their instructions got the VPN running, but no traffic was passing. This guide showed me the firewall rules I needed to get things really working.

                          Also, pfSense running on an old HP7900 SFF pc is easily handling my 50/25 Mb/s connection.  I gotta thank the hardware forum for that recommendation.

                          may i ask the name of the provider you mentioned?
                          just cuorious if that provider is cheaper.

                          1 Reply Last reply Reply Quote 0
                          • T
                            tjabas
                            last edited by

                            i Think that i have managed to get strongvpn up and running, but i cant get any internet access, i can ping to different sites from the router but i cant get any internet access to my computers.

                            if i look at the logs it seems like the vpn is up and running,

                            please help!

                            1 Reply Last reply Reply Quote 0
                            • T
                              tjabas
                              last edited by

                              no im finally up and running, but the speed tests is not good, i have a 100mb line down, and with openvpn i get only 1mb down, and that sucks, but i have changed location on the strongvpn webbpage, but what do i have to change in my settings in pfsense to get the new location to work?
                              i tried to change just the ip number but it didnt work.

                              please help

                              1 Reply Last reply Reply Quote 0
                              • R
                                richardkingsley
                                last edited by

                                For different location / server you need to redo the process again with the new certificate details as each of the servers have a different cert / key. Once you have got it working once it only takes a few minutes.

                                I am finding that the strongvpn connection very slow and am looking for alternatives

                                Richard

                                1 Reply Last reply Reply Quote 0
                                • T
                                  tjabas
                                  last edited by

                                  @richardkingsley:

                                  For different location / server you need to redo the process again with the new certificate details as each of the servers have a different cert / key. Once you have got it working once it only takes a few minutes.

                                  I am finding that the strongvpn connection very slow and am looking for alternatives

                                  Richard

                                  thank you, yes im also looking for alternatives, anyone who has any suggestions?

                                  1 Reply Last reply Reply Quote 0
                                  • M
                                    max.i
                                    last edited by

                                    anyone made this work recently? I'm running 2.1 release from Sep 11 2013 - the virtual machine.

                                    I've disabled every other package I had (dansguardian/squid) and ensured the configuration was exactly as specified. The VPN shows as up, and I can ping the remote addresses but cannot access anything on the internet.

                                    Thanks!

                                    1 Reply Last reply Reply Quote 0
                                    • F
                                      Fevan
                                      last edited by

                                      Hi got some questions regarding this guide and other variations of other peoples guides.

                                      1. Is Monitor IP and 208.67.222.222 important ?  I did not understand what graph displays and load balancer meant and was not comfortable with using an OpenDNS US based server.

                                      2. I noticed in a few other peoples guides with strong vpn and other providers they are always adding other firewall rules ie ones for Wan and even strong or their VPN, yet this guide only states you need to add firewall rules for LAN only. The guys that did WAN and VPN firewall rules said otherwise it did not work….

                                      3. Has any Pfsense+VPN user noticed if they leave there pfsense on 24/7 sometimes it looses connection ?

                                      as in overnight or after 24 or 48hrs ?  I have this issue where the following morning if I switch on the PC webpages are not loading, if I wait 3-4 mins it then "jump" starts and works again, I believe the issue is since I leave my pfsense pc switched on 24/7. Rebooting the pfsense box sometimes restarts quicker or sometimes still have to wait 3-4 mins for it to magically come on. My gut tells me the handshake is lost once connection is idle for more then few hours?

                                      any answers to the above are weclome thanks

                                      1 Reply Last reply Reply Quote 0
                                      • P
                                        powerextreme
                                        last edited by

                                        I am working on this setup. I have gotten to step 10. So far I am able to get the OpenVPN client up and running. I have noticed at this point internet connectivity goes down. DNS still works but can't ping to IP's on the Internet.

                                        I know I am only at step 10 but just curious as to what happened when I started the OpenVPN client service.

                                        Anyone got any ideas?

                                        1 Reply Last reply Reply Quote 0
                                        • D
                                          dawilder
                                          last edited by

                                          Hi everyone.  Total NOOB here.

                                          I've been trying to get a StrongVPN client set up on pfSense latest version (2.1.3).

                                          I tried the initial tutorial by ericab, who started this thread, as well as the tutorial in the link by pkwong.  However, after a certain point, the screenshots start to differ slightly (in terms of the options) and I can't figure out what I'm doing wrong.  Also, on my machine, it seems to distinguish between IPv4 and IPv6 LANs.  Not sure if that is part of my problem.  That's above my head at this point.  I'm reeeaaaly clueless about this stuff, so your guys hand-holding is really appreciated.

                                          I was able to load all the certificate information and get a positive indication of connection under system logs.  One other thing I noticed,  when I set up the certificate, I did not get an "in-use" indication within the GUI, like you see for the other one that was already there.  Could that be part of the problem?

                                          If there is an updated tutorial, or if it's known that a StrongVPN Client will not work with the latest version of pfSense, I'd greatly appreciate the help.

                                          Thanks!
                                          DW

                                          1 Reply Last reply Reply Quote 0
                                          • T
                                            tucansam
                                            last edited by

                                            What alternative(s) to StrongVPN have you folks found?  I was looking at privateinternetaccess but, like others, the tutorials I find online are for older versions, and as this will be my first time doing something like this, I'm going to need a lot of help.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.