Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN Portal?

    Scheduled Pinned Locked Moved General pfSense Questions
    8 Posts 6 Posters 3.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • U
      usual
      last edited by

      One thing I liked about Sophos was the ability to have a VPN Portal where you could authenticate and then download the various VPN client packages to get connected.

      Can pfsense do this?

      1 Reply Last reply Reply Quote 0
      • D
        divsys
        last edited by

        There isn't a specific "Portal" to accomplish this.

        One way you can achieve some of this capability is to create a login user and give them only access the OpenVPN Client Export page.

        Unfortunately they would still have access to all the available clients for that pfSense box.
        It would be nice if you could limit them to only "their" specific client choices.

        I suspect we might be opening a potentially larger can of worms here in terms of secure access to pfSense by users that will only need very limited access.
        On the one hand it's definitely nice to have from the client's POV, on the other I don't know how much work we're talking about to enforce user security at that level.

        Would be nice to have though  :)

        -jfp

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Are you talking about a portal like the openvpn access server has?

          If you give the user the config, they can use that config in any client they want to use normal.  Be it windows, linux or ios type device.  Not sure I see the point of a portal to be honest.  You could always run the openvpn access server, but that is limited to 2 concurrent connections unless you buy licenses from them.. And it doesn't run on pfsense - wonder if there would be a way to run the AS on pfsense vs the open community version?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • U
            usual
            last edited by

            The convenience I guess. I could just be on a computer anywhere open a browser authenticate and grab the client package.

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              This request pops up frequently but we are really hesitant to allow it for security reasons. If you setup this nice, secure VPN with user certs, TLS auth, authentication, etc, and then you allow anyone with their username and password to download the client, you have effectively nullified all of your extra authentication factors. Especially if you allow such access remotely! It's really, really dangerous to do that. Anyone that has the password anywhere in the world could just login and get full access to your network.

              If you're doing that, you may as well just have a VPN with no per-user certs, just user auth, and then everyone can use the same client. And in that case, you don't need a per-user download, which eliminates the need for the feature entirely.

              Until a secure method of allowing user access to download such things can be designed, it's not a good idea. It is convenient, sure, but not secure.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • U
                usual
                last edited by

                Good points. Thanks.

                1 Reply Last reply Reply Quote 0
                • B
                  barrio603
                  last edited by

                  With no user portal how do not spend a huge amount of time to get 100 users the VPN Client with their specific SSL certificate.

                  I do not see a security issue to download a client and cert especially of the user is authenticated against a LDAP or RADIUS server.

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    This thread is ancient but the same thing applies. If you need to be doing something like that you should use a dedicated authentication server that has options like that.

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S stephenw10 locked this topic on
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.