Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Openvpn wrapped by stunnel

    Scheduled Pinned Locked Moved pfSense Packages
    11 Posts 8 Posters 5.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z
      zqoot
      last edited by

      Hi

      openvpn protocol got blocked in my country (tcp udp different ports).

      I heard that stunnel can wrap openvpn traffic to normal ssl so that DPI not easily identify.

      my vpn provider having stunnel ssl options and openvpn of course.

      I have searched many sites but nothing for pfsense.

      vpn provider provide stunnel.conf and CA certificate (.pem)

      Is there any guide (step by step) how to run stunnel ?

      I have tried but always getting certificate error.

      i am willing to connect as a client only.

      Thanks

      1 Reply Last reply Reply Quote 1
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        There are no guides and that's typically a bad idea anyhow.

        Use pfSense 2.4 and activate OpenVPN 2.4's "TLS Crypt" mode instead. Assuming both sides support that, it encrypts the control channel making it more difficult to identify. No need to run it through yet another layer of encapsulation.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • A
          akha666
          last edited by

          Hello TLS Crypt didn't help me.
          I have the same issue , our ISPs using DPI to block VPN Traffic.
          https://www.bestvpn.com/egypt-blocks-openvpn
          any workaround ?

          1 Reply Last reply Reply Quote 0
          • A
            akha666
            last edited by

            finally got ovpn working again over stunnel.
            stunnel is the best workaround for this issue.
            stunnel package back again to new pfsense 2.4.

            D V 2 Replies Last reply Reply Quote 0
            • A
              awair
              last edited by

              Hi Akha,

              Would you care to share…

              Screenshots would be great.

              Many thanks.

              2.4.3 (amd64)
              and given up on the SG-1000

              1 Reply Last reply Reply Quote 0
              • A
                awair
                last edited by

                @jimp:

                Use pfSense 2.4 and activate OpenVPN 2.4's "TLS Crypt" mode instead.

                Where is this option? Is this the TLS KEY Usage Mode or is it added to Custom options?

                Many thanks

                2.4.3 (amd64)
                and given up on the SG-1000

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  Its right there in the VPN settings.. Drop down..

                  See attached pic

                  tlsencrypt.png
                  tlsencrypt.png_thumb

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • A
                    awair
                    last edited by

                    Thanks John,

                    I've since tried that option and it doesn't help my case. Looks like STunnel is the only realistic proposition for keeping OpenVPN running.

                    I've got that working on a client computer, but would much prefer to share this where needed.

                    2.4.3 (amd64)
                    and given up on the SG-1000

                    1 Reply Last reply Reply Quote 0
                    • M
                      MR-NT
                      last edited by

                      i have the same issue , i think Stunnel is my last hope

                      1 Reply Last reply Reply Quote 0
                      • D
                        dfindlay @akha666
                        last edited by

                        @akha666

                        I'm having similar issues trying to setup stunnel to openvpn. Im using openvpn on pfsense as my server and on the receiving end client also using openvpn on pfsense. I would like to setup stunnel as client and server in their respective locations.

                        Can you assist?

                        1 Reply Last reply Reply Quote 0
                        • V
                          Vestinglama @akha666
                          last edited by

                          @akha666 Hello please how were you able to configure the stunnel to work with your OVPN. I keep trying to do the configuration on my pfsense but it doesnt work

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.