Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WAN Interface OpenVPN Bug question..

    Scheduled Pinned Locked Moved OpenVPN
    42 Posts 4 Posters 6.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      comet424
      last edited by

      and its probably something all vpn services run into or openvpn client i just not good enough yet to understand it all i just try to google information and ask in here. i

      1 Reply Last reply Reply Quote 0
      • H
        heper
        last edited by

        WAN_PPPOE gateway seems odd to me ... ? its in rfc1918 address space
        also:

        • please post your fw rules
        • post the routing table on dhcp, dhcp_withvpn_enabled, pppoe, pppoe_withvpn_enabled
        1 Reply Last reply Reply Quote 0
        • C
          comet424
          last edited by

          what you mean gateway seems odd to you for PPPOE? whats a rfc1918 address.. you need to explain.. still new to pfsesnse and i dont know what most of it it does etc
          and how you get this routing table i only have 2 routing spots
          3_1532784274286_firewall4.JPG 2_1532784274286_firewall3.JPG 1_1532784274286_firewall2.JPG 0_1532784274286_firewall1.JPG

          1 Reply Last reply Reply Quote 0
          • C
            comet424
            last edited by

            0_1532784670801_firewall5.JPG

            1 Reply Last reply Reply Quote 0
            • C
              comet424
              last edited by

              from what i was told by NordVPN its a pfsense bug problem its not there sides fault
              that VPN can not get the right ip address from PFsense in PPPOE mode
              ugh one headache after another

              1 Reply Last reply Reply Quote 0
              • C
                comet424
                last edited by

                how do i fix that..
                this is what they wrote me "it seems that once you are connected with the PPPoE, the VPN cannot get the correct gateway to access the Internet and therefore fails. The only proper way to resolve this issue is to use the DHCP on the WAN interface."

                since DHCP mode works for VPN Nord Service.. but i loose Remote Access to the network so cant access my local network.. i seem to only be able to access it via PPPOE but if there is a way to get Remote Access to the network to work on a Local network be great.. as it hangs on me and then gives me TLS error

                Sat Jul 28 12:24:42 2018 OpenVPN 2.4.4 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Sep 26 2017
                Sat Jul 28 12:24:42 2018 Windows version 6.2 (Windows 8 or greater) 64bit
                Sat Jul 28 12:24:42 2018 library versions: OpenSSL 1.0.2l 25 May 2017, LZO 2.10
                Sat Jul 28 12:24:46 2018 TCP/UDP: Preserving recently used remote address: [AF_INET]174.94.28.150:1196
                Sat Jul 28 12:24:46 2018 UDP link local (bound): [AF_INET][undef]:1194
                Sat Jul 28 12:24:46 2018 UDP link remote: [AF_INET]x.x.x.x:1196

                and thats all i get but if i set the PPPOE on Wan interface she will connect right in..
                its a frustrating as hell and i try googling but i really dont know what i trying to google as people word things different

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  @comet424 said in WAN Interface OpenVPN Bug question..:

                  Sat Jul 28 12:24:46 2018 UDP link local (bound): [AF_INET][undef]:1194
                  Sat Jul 28 12:24:46 2018 UDP link remote: [AF_INET]x.x.x.x:1196

                  Again, it looks like you bound your local port to 1194. Why?

                  0_1532806165415_Screen Shot 2018-07-28 at 12.27.53 PM.png

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • C
                    comet424
                    last edited by

                    as you can see i didnt set it to 11940_1532806590508_firewall6.JPG

                    1 Reply Last reply Reply Quote 0
                    • C
                      comet424
                      last edited by

                      i have no idea why 1194 shows up is there another spot for it

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        That is a server, not a client.

                        Why are you posting Windows client logs when we're talking about connecting pfSense to a VPN service? Where does windows fit in?

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • C
                          comet424
                          last edited by

                          what.

                          what i wrote at the top is what i said
                          2 Issues
                          2 problems that need fixing

                          1 NordVPN
                          2. OpenVPN Remote Access

                          both Work in opposite scenarios
                          of the WAN Interface

                          and like i said.. is this a PFSENSE Bug problem
                          that neither NordVPN and OpenVpn Remote Access
                          can work together at the same time...

                          like i posted in the other form asking similar question

                          WAN Interface (DHCP) ------>>> NORDVPN (works) ------>>> OpenVPN Remote Access (Doesnt)

                          WAN Interface (PPPOE) ----->>> NORDVPN(doesn work) ----->>> OpenVPN Remote Access (Works)

                          thats why i mentioned NordVPN says its a Pfsense problem why NordVPN doesnt work right
                          as i want both working in either DHCP or PPPOE

                          DerelictD 1 Reply Last reply Reply Quote 0
                          • C
                            comet424
                            last edited by comet424

                            thats why the 3rd line of my first post states i dealing 2 issues on Pfsense that seem to be a Bug Problem with Pfsense.. since i asked also if its a Check mark that i have to check off on an option etc..

                            1 Reply Last reply Reply Quote 0
                            • DerelictD
                              Derelict LAYER 8 Netgate
                              last edited by

                              If you are screwing around with static source ports you might very well be creating a conflict there.

                              There is no set limitation to running simultaneous clients and servers. Look at your client configurations. You should NOT be setting local ports there.

                              You should probably check "Use random local port" when you export the remote access client configurations.

                              You are going to have to post complete OpenVPN configurations for the server and all of your clients - or at least the ones you are trying to run.

                              Chattanooga, Tennessee, USA
                              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                              Do Not Chat For Help! NO_WAN_EGRESS(TM)

                              1 Reply Last reply Reply Quote 0
                              • DerelictD
                                Derelict LAYER 8 Netgate @comet424
                                last edited by

                                @comet424 said in WAN Interface OpenVPN Bug question..:

                                WAN Interface (DHCP) ------>>> NORDVPN (works) ------>>> OpenVPN Remote Access (Doesnt)
                                WAN Interface (PPPOE) ----->>> NORDVPN(doesn work) ----->>> OpenVPN Remote Access (Works)

                                I have never seen a wan that you can just switch from PPPoE to DHCP. They are provisioned either one way or the other. So I don't know what you're talking about here either.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • C
                                  comet424
                                  last edited by comet424

                                  it says it right there click it DHCP or PPPOE on the WAN InterFace0_1532811387562_firewall7.jpg

                                  like i stated
                                  Set WAN Interface to DHCP 1 works other doesnt
                                  Set WAN Interface to PPPOE vice versa

                                  1 Reply Last reply Reply Quote 0
                                  • C
                                    comet424
                                    last edited by comet424

                                    thats why i asked is this a Bug issue or is a check off a checkbox issue..
                                    since NordVPN said its a pfsense problem its not there side problem that Nord VPN cant get the ip address

                                    also if made sense if you watched my youtube video is shows you exactly the problem you click WAN and choose it.. it was all in that video i posted scroll up
                                    and like i said it doesnt show the OpenVPN Remote Access for the network just the NordVPN

                                    4th Message from the Top of the article showed you exactly my issues shows you the video i posted

                                    1 Reply Last reply Reply Quote 0
                                    • DerelictD
                                      Derelict LAYER 8 Netgate
                                      last edited by

                                      No I get that. But the ISP connection is generally provisioned one way or the other. Your setting has to match the provisioning.

                                      Chattanooga, Tennessee, USA
                                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                      1 Reply Last reply Reply Quote 0
                                      • DerelictD
                                        Derelict LAYER 8 Netgate
                                        last edited by

                                        Yeah. Not going to be watching any videos. Sorry.

                                        Chattanooga, Tennessee, USA
                                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                        1 Reply Last reply Reply Quote 0
                                        • C
                                          comet424
                                          last edited by

                                          not sure what you mean match the provisioning.. but thanks anyways

                                          so guess back to being i guess a pfsense bug in the software
                                          here i was hoping it be a Check this box off if you use PPPOE for VPN Services or uncheck this box if you using DCHP

                                          hopefully someone else might have an answer for this frustrating issue

                                          1 Reply Last reply Reply Quote 0
                                          • DerelictD
                                            Derelict LAYER 8 Netgate
                                            last edited by

                                            @comet424 said in WAN Interface OpenVPN Bug question..:

                                            Bell Canada

                                            Don't forget that you probably have another device in front of the router that might be causing your problems. Some "Home Hub" or something.

                                            Countless people using OpenVPN clients and PPPoE. Not sure what Nord's problem is. They have to blame something I guess.

                                            Chattanooga, Tennessee, USA
                                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.