Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Ensuring against IP leaks - a challenge?

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 5 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      So, my question is really - Does anyone else get unexpected results using http://whatismyip.host?

      No.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • M
        MoonKnight
        last edited by

        @tonynibbles:

        So, my question is really - Does anyone else get unexpected results using http://whatismyip.host?

        No :)

        --- 24.11 ---
        Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
        Kingston DDR4 2666MHz 16GB ECC
        2 x HyperX Fury SSD 120GB (ZFS-mirror)
        2 x Intel i210 (ports)
        4 x Intel i350 (ports)

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          This post actually looks like spam.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • T
            tonynibbles
            last edited by

            Well, it might be a bit wordy but I can assure you it's not spam - a genuine query as to whether this is just me or not.

            Thanks for the replies, I'm still at a loss as to where my fault is and why this site and only this site reports my IP, but I will persevere.

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              So I just turned my policy route rule to send client out vpn.  I then made sure client was using quad9 for dns vs pfsense as resolver and hit up whats my IP and your website both showing my vpn IP.. So not sure what your doing exactly.  But without details it will be impossible for anyone to help you spot what your doing wrong, etc.

              Turned policy rule off and back to my normal wan IP from isp.

              policyroutepng.png
              policyroutepng.png_thumb
              Selection_027.png
              Selection_027.png_thumb

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                @tonynibbles:

                Well, it might be a bit wordy but I can assure you it's not spam - a genuine query as to whether this is just me or not.

                Thanks for the replies, I'm still at a loss as to where my fault is and why this site and only this site reports my IP, but I will persevere.

                It is showing your IP address because you have your system configured to send it out the WAN not the OpenVPN.

                No way to know what in your configuration is wrong unless you show us what you have done.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • T
                  tonynibbles
                  last edited by

                  Well, fwiw my system setup uses much of the advice in the techhelpguides article, VPNs are configured as a Gateway group consisting of four VPN connections, the load balancing handles when one becomes too slow.

                  A firewall rule on the LAN tells all outbound traffic to use the VPN Gateway Group.

                  I'm a little less familiar with the DNS setup, but I've used the DNS Resolver method ("Leak Prevention Method 2") from the tech help guides.

                  My setup appears to work well, apart from this one site which reports my IP. Everything else, Google, dnsleak, ipleak, whatismyip - they all report my VPN IP. This is why it's so frustrating - something's getting through but I can't be sure how.

                  There are so many settings in PFsense it seems impossible to convey every detail of my config - I suppose a better question would be, what tools do people use to debug this?

                  ![Screen Shot 2018-04-16 at 23.01.14.png](/public/imported_attachments/1/Screen Shot 2018-04-16 at 23.01.14.png)
                  ![Screen Shot 2018-04-16 at 23.01.14.png_thumb](/public/imported_attachments/1/Screen Shot 2018-04-16 at 23.01.14.png_thumb)

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    Packet captures and wireshark.

                    Diagnostics > States

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • T
                      tonynibbles
                      last edited by

                      Hmmm, ok.

                      Now in states, I can see that if I use Google.com, the request uses one of my VPN connections, but on the other website, the request goes out on WAN. Damn.

                      1 Reply Last reply Reply Quote 0
                      • T
                        tonynibbles
                        last edited by

                        FFFFFFFF

                        OK. I've got it!

                        I am running pfBlocker and have it set to create an alias group of Amazon servers. Requests to these destination IPs are set to bypass the VPN (mostly for content streaming), but in this case because that website was hosted on AWS, it was being delivered on the WAN not the VPN. Hence, it could see my IP.

                        This is the dumbest thing. Thanks for the heads up on figuring this out, was doing my nut in.
                        What a doofus.

                        1 Reply Last reply Reply Quote 0
                        • P
                          pdfteam
                          last edited by

                          No. I am getting same IP results with whatismyip.host and other  websites such as whatismyip.live

                          I am using PureVPN and visited both websites. Here are the results:

                          http://whatismyip.live  IP results:

                          http://whatismyip.host results:

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.