Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Openvpn topology

    OpenVPN
    2
    7
    674
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      choko
      last edited by

      hi,i try to make a site to site openvpn vpn ,can you tell me if this topology can work correctly .
      ![plan test.jpg](/public/imported_attachments/1/plan test.jpg)
      ![plan test.jpg_thumb](/public/imported_attachments/1/plan test.jpg_thumb)

      1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott
        last edited by

        At first glance, it appears OK, but why do you have a /25 on the tunnel?  You'd normally use a /30 there.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • C
          choko
          last edited by

          as i had understood,the ip tunnel will be affected to each host in the tunnel vpn , so if i get ip/30 i wont be able to connect every host through the tunnel , is it correct ?

          1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott
            last edited by

            @choko:

            as i had understood,the ip tunnel will be affected to each host in the tunnel vpn , so if i get ip/30 i wont be able to connect every host through the tunnel , is it correct ?

            No that's not correct.  Connections are routed through the tunnel, but it doesn't limit the number of addresses on the other side.  Think of your Internet connection.  You have a single address on your firewall/router, but can reach every address out there.  As I mentioned, a /30 is typically used, but even a /31 can be used, if the tunnel end points support it.

            To understand this, take a look at how routing works.  When a computer sends a packet to a destination that's not on the local network, it forwards it through the router or gateway.  The router then looks at the destination address and sends it on appropriately, eventually reaching the destination network.  At that point the router will send it to the desired device.  So, you only need enough addresses on the network where the devices are located.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • C
              choko
              last edited by

              thank you for the help, i will change that and notice you in the end of work

              1 Reply Last reply Reply Quote 0
              • C
                choko
                last edited by

                hi, i tried like you tell me but it not work,i think there is something addionnal that i forget to do. there is a screen with all conf ( server+ client) and the log (server+client). it still want connect and i cant find the problem :(

                ![server openvpn.jpg](/public/imported_attachments/1/server openvpn.jpg)
                ![server openvpn.jpg_thumb](/public/imported_attachments/1/server openvpn.jpg_thumb)
                ![firewall rule server.jpg](/public/imported_attachments/1/firewall rule server.jpg)
                ![firewall rule server.jpg_thumb](/public/imported_attachments/1/firewall rule server.jpg_thumb)
                ![log server.jpg](/public/imported_attachments/1/log server.jpg)
                ![log server.jpg_thumb](/public/imported_attachments/1/log server.jpg_thumb)
                ![client openvpn.jpg](/public/imported_attachments/1/client openvpn.jpg)
                ![client openvpn.jpg_thumb](/public/imported_attachments/1/client openvpn.jpg_thumb)
                ![firewall rule client.jpg](/public/imported_attachments/1/firewall rule client.jpg)
                ![firewall rule client.jpg_thumb](/public/imported_attachments/1/firewall rule client.jpg_thumb)
                ![log client.jpg](/public/imported_attachments/1/log client.jpg)
                ![log client.jpg_thumb](/public/imported_attachments/1/log client.jpg_thumb)

                1 Reply Last reply Reply Quote 0
                • C
                  choko
                  last edited by

                  hi,i resolved the problem,its the modem who has blocked the cnx on the vpn server ,now its work.
                  bue another question please,should i change the encryption to ssl or even with shared key its securised a lot .

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.