Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Issues with OpenVPN Configuration

    Scheduled Pinned Locked Moved OpenVPN
    73 Posts 6 Posters 19.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      dhendriksen
      last edited by

      @kejianshi:

      OK - Baby steps…

      I want you to change a few things if thats ok?

      Force all client generated traffic through the tunnel.

      Also, provide DNS Servers.

      192.168.1.1
      8.8.8.8

      I'm down with the baby steps, but let me make sure I understand. You want me to recheck the DNS servers box in the VPN config, and add those 2 DNS servers?

      1 Reply Last reply Reply Quote 0
      • K Offline
        kejianshi
        last edited by

        Please make the initial changes to the openvpn server that I suggested.  Then test it.

        BTW - How are you seeing your server config if you are away and your VPN isn't working?

        "You want me to recheck the DNS servers box in the VPN config, and add those 2 DNS servers?" - Yes

        I want you to use your pfsense LAN as DNS server (192,168.1.1) and if something on your local network interferes with that, like the subnet in use, 8.8.8.8, just in case.

        Just temporary to ensure you have DNS.

        BTW - What kind of phone?  What is the openvpn client software being used?

        1 Reply Last reply Reply Quote 0
        • D Offline
          dhendriksen
          last edited by

          @kejianshi:

          Please make the initial changes to the openvpn server that I suggested.  Then test it.

          BTW - How are you seeing your server config if you are away and your VPN isn't working?

          I'm not away. I'm at home. I've got computers that are hard wired on the LAN here. I'm testing it from mobile phones and hotspots.

          I think I made those changes correctly. I'm going to test it now.

          Screenshot_2015-02-20-00-02-21.png
          Screenshot_2015-02-20-00-02-21.png_thumb

          1 Reply Last reply Reply Quote 0
          • D Offline
            dhendriksen
            last edited by

            I made those changes. The VPN from my phone still works the same. Do I need to redownload the client export after making those changes?

            1 Reply Last reply Reply Quote 0
            • D Offline
              dhendriksen
              last edited by

              Just saw the edits to your last post. It's an Android phone. Google Nexus 6. I'm using the "OpenVPN Connect" client.

              1 Reply Last reply Reply Quote 0
              • K Offline
                kejianshi
                last edited by

                Not yet.  Now I'd like to see the:

                Firewall: Rules

                The LAN tab and the OpenVPN tab.

                1 Reply Last reply Reply Quote 0
                • D Offline
                  dhendriksen
                  last edited by

                  @kejianshi:

                  Not yet.  Now I'd like to see the:

                  Firewall: Rules

                  The LAN tab and the OpenVPN tab.

                  As requested. Thanks again for your help.

                  ![Firewall Rules LAN Tab.jpg](/public/imported_attachments/1/Firewall Rules LAN Tab.jpg)
                  ![Firewall Rules VPN Tab.jpg](/public/imported_attachments/1/Firewall Rules VPN Tab.jpg)
                  ![Firewall Rules LAN Tab.jpg_thumb](/public/imported_attachments/1/Firewall Rules LAN Tab.jpg_thumb)
                  ![Firewall Rules VPN Tab.jpg_thumb](/public/imported_attachments/1/Firewall Rules VPN Tab.jpg_thumb)

                  1 Reply Last reply Reply Quote 0
                  • D Offline
                    dhendriksen
                    last edited by

                    I should reiterate that when connecting from my Windows8 laptop it works swimmingly. The problem just seems to exist when I connect with this Android phone.

                    It can see some devices/IP's, but can't see 192.168.1.1. AND the apps on my phone won't connect to the local LAN. It's as if they're still using the cellular connection.

                    1 Reply Last reply Reply Quote 0
                    • K Offline
                      kejianshi
                      last edited by

                      Have you tried rebooting the phone?

                      1 Reply Last reply Reply Quote 0
                      • D Offline
                        dhendriksen
                        last edited by

                        Not in the last few hours. Will do that now.

                        1 Reply Last reply Reply Quote 0
                        • D Offline
                          dhendriksen
                          last edited by

                          @kejianshi:

                          Have you tried rebooting the phone?

                          Rebooting the phone made no difference. Still functions the same.

                          1 Reply Last reply Reply Quote 0
                          • K Offline
                            kejianshi
                            last edited by

                            How are you testing the connection?

                            1 Reply Last reply Reply Quote 0
                            • D Offline
                              dhendriksen
                              last edited by

                              @kejianshi:

                              How are you testing the connection?

                              Over the LTE/cellular network.

                              1 Reply Last reply Reply Quote 0
                              • K Offline
                                kejianshi
                                last edited by

                                Can you connect your phone then go to:

                                Status: OpenVPN

                                Post what is on that page.

                                1 Reply Last reply Reply Quote 0
                                • D Offline
                                  dhendriksen
                                  last edited by

                                  @kejianshi:

                                  Can you connect your phone then go to:

                                  Status: OpenVPN

                                  Post what is on that page.

                                  As requested.

                                  ![VPN Status.jpg](/public/imported_attachments/1/VPN Status.jpg)
                                  ![VPN Status.jpg_thumb](/public/imported_attachments/1/VPN Status.jpg_thumb)

                                  1 Reply Last reply Reply Quote 0
                                  • K Offline
                                    kejianshi
                                    last edited by

                                    And while its connected, in the phone browser, if you type

                                    https://192.168.1.1  -  What does this get?

                                    https://www.google.com - What does this get?

                                    https://192.168.79.1  -  What does this get?

                                    1 Reply Last reply Reply Quote 0
                                    • D Offline
                                      dhendriksen
                                      last edited by

                                      @kejianshi:

                                      And while its connected, in the phone browser, if you type

                                      https://192.168.1.1  -  What does this get?

                                      https://www.google.com - What does this get?

                                      https://192.168.79.1  -  What does this get?

                                      They all yield the same result. Nothing loads.

                                      Screenshot_2015-02-20-00-46-38.png
                                      Screenshot_2015-02-20-00-47-19.png
                                      Screenshot_2015-02-20-00-46-38.png_thumb
                                      Screenshot_2015-02-20-00-47-19.png_thumb

                                      1 Reply Last reply Reply Quote 0
                                      • K Offline
                                        kejianshi
                                        last edited by

                                        Try deleting the configuration off your phone.  Export the configuration from pfsense openvpn client export.

                                        Reinstall and retry.

                                        If its still broken I have to imagine there is something up with either the LTE service causing problems or the phone its self.

                                        1 Reply Last reply Reply Quote 0
                                        • DerelictD Offline
                                          Derelict LAYER 8 Netgate
                                          last edited by

                                          Instead of troubleshooting with a phone do you have a laptop so you can run some real troubleshooting tools?

                                          Chattanooga, Tennessee, USA
                                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                          1 Reply Last reply Reply Quote 0
                                          • K Offline
                                            kejianshi
                                            last edited by

                                            It might be useful to take the phone, share its LTE connection via hotspot to the laptop and test openvpn on the laptop connected via the hotspot to see if its LTE connection thats breaking things or if its something particular to the phone its self.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.