Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Subdomain for VPN Access

    OpenVPN
    5
    5
    3.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      brownatron
      last edited by

      Hi All,
      I just built my first ever pfSense box as I'm looking to understand more about networking and I figured this is the best way to learn!

      I've got my VPN configured and pointing to my ip address but ideally I want it only to work on vpn.mydomain.com if at all possible!
      I have no idea how to do this however - I own my domain name and have access to SRV and CNAME's etc.

      So far all I've done is create a vpn.mydomain.com CNAME that points to @ - I'm not really sure where to go from here?
      Do I need to set some hostname on my pfSense box?

      In case it helps: I'm running the pfSense router (no DHCP), a Windows Server 2016 box with AD, DNS, DHCP and a small website in IIS.

      Any and all guidance would be very much appreciated!

      1 Reply Last reply Reply Quote 0
      • F
        flynjets
        last edited by

        vpn.mydomain.com needs to be an A record that points to your external IP address assuming is statically assigned. If it's not statically assigned you'll want to setup a dynamic DNS service to keep it updated (Cloudflare, noip.com, etc.)

        1 Reply Last reply Reply Quote 0
        • jahonixJ
          jahonix
          last edited by jahonix

          @brownatron

          do you want to reach vpn.mydomain.com from the inside or externally (or both) ?

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            The VPN server has absolutely no idea whether the connecting client got the name from a DNS lookup or used an IP address. As far as the server is concerned, the connections are all to the IP address.

            ideally I want it only to work on vpn.mydomain.com if at all possible!

            Not sure what that means, actually. If you want the most security out of your VPN, use RSA keys and IPsec or OpenVPN in SSL/TLS + User Auth mode.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • M
              marvosa
              last edited by

              As flynjets already stated, for your subdomain, change your DNS record type to an A record pointed at your IP instead of a CNAME.

              If you want your clients to connect using your vpn.mydomain.com subdomain instead of an IP, that change is made during client export. I.e. change the Host Name Resolution option to "Other" and enter vpn.mydomain.com in the Hostname box.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.