Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    RDP wont work on FullTAP?

    Scheduled Pinned Locked Moved OpenVPN
    21 Posts 5 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GilG
      Gil Rebel Alliance
      last edited by

      Looks like you are not connecting and have no routing at all.
      Not really an RDP issue

      11 cheers for binary

      1 Reply Last reply Reply Quote 1
      • P
        profIT @profIT
        last edited by

        @profit @Gil should clarify *i still get routed connection and am on local network despite those errors."

        1 Reply Last reply Reply Quote 0
        • M
          Milkwyrm
          last edited by

          seems to be a fairly common issue.
          https://forum.netgate.com/topic/113174/tls-error-local-remote-tls-keys-are-out-of-sync

          https://www.google.com/search?q=TLS+Error%3A+local%2Fremote+TLS+keys+are+out+of+sync&ie=utf-8&oe=utf-8&client=firefox-b

          You might want to start over. I always try to find at least 3 articles/how-to's for any setup I'm not experienced with and cheery pick the parts that are common between them to figure it out. My primary PFsense unit runs 13 IPSEC site-to-site tunnels and 2 Ovpn client/server instances and one Ovpn site-to-site without issue from day one, so it's definitely a rock solid solution once you figure it out.

          P 1 Reply Last reply Reply Quote 1
          • P
            profIT @Milkwyrm
            last edited by

            @milkwyrm reconfigured my server, created new users and that TLS thing is gone, and I connect to the network with no problems now, I can browse the internet and sign into pfsense gui.

            However, still cannot ping anything on the network

            ☺

            P 1 Reply Last reply Reply Quote 0
            • P
              profIT @profIT
              last edited by

              @profit i want to mention im not on a different subnet either, im actually bridged onto the LAN. Is this the moment where i post my config file in here?

              1 Reply Last reply Reply Quote 0
              • M
                Milkwyrm
                last edited by

                Is there a particular reason you have for using a bridged network? I'm guessing from the first post this is a road warrior vpn rather than a static site to site connection.
                Are you using local Auth, or AD for your users.
                can you post the config for both ends (minus any sensitive info).

                1 Reply Last reply Reply Quote 1
                • P
                  profIT
                  last edited by

                  @Milkwyrm No particular reason. Am using local auth.

                  • Language-dev
                  • Language-kotlin
                  verb 1
                  dev-type tap
                  dev-node /dev/tap1
                  writepid /var/run/openvpn_server1.pid
                  #user nobody
                  #group nobody
                  script-security 3
                  daemon
                  keepalive 10 60
                  ping-timer-rem
                  persist-tun
                  persist-key
                  proto udp4
                  cipher AES-128-CBC
                  auth SHA1
                  up /usr/local/sbin/ovpn-linkup
                  down /usr/local/sbin/ovpn-linkdown
                  client-connect /usr/local/sbin/openvpn.attributes.sh
                  client-disconnect /usr/local/sbin/openvpn.attributes.sh
                  local x.x.x.x
                  engine rdrand
                  tls-server
                  mode server
                  push "route-gateway 10.0.1.1"
                  username-as-common-name
                  auth-user-pass-verify "/usr/local/sbin/ovpn_auth_verify user TG9jYWwgRGF0YWJhc2U= false server1 1194" via-env
                  tls-verify "/usr/local/sbin/ovpn_auth_verify tls 'ServerCert' 1"
                  lport 1194
                  management /var/etc/openvpn/server1.sock unix
                  push "redirect-gateway def1"
                  client-to-client
                  ca /var/etc/openvpn/server1.ca 
                  cert /var/etc/openvpn/server1.cert 
                  key /var/etc/openvpn/server1.key 
                  dh /etc/dh-parameters.2048
                  tls-auth /var/etc/openvpn/server1.tls-auth 0
                  ncp-ciphers AES-256-GCM:AES-128-GCM
                  fast-iojava
                  
                  <
                  1 Reply Last reply Reply Quote 0
                  • P
                    profIT
                    last edited by

                    Forget RDP not working, I'm having trouble connected to a mapped network drive at the office...

                    1 Reply Last reply Reply Quote 0
                    • GilG
                      Gil Rebel Alliance
                      last edited by

                      Have you set up your routing?
                      It is possible to have an openvpn connection but no routing.

                      11 cheers for binary

                      1 Reply Last reply Reply Quote 0
                      • T
                        ThatGuy
                        last edited by

                        I've got a really stupid question but have you rebooted your pfSense box (on both ends if it's site-to-site). I had some trouble last week getting an OpenVPN connection set up. I've done it so many times I can't remember. I even wrote myself a step by step tutorial a few months ago just in case. But no matter how many times I reset everything and started over I couldn't ping the other side. Even tried resetting the firewall states after re-configuring.

                        I rebooted the pfSense boxes on both ends and BAM! It worked fine.

                        Last thought, you've got the firewall rules in pfSense, right?

                        ThatGuy

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.