Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    only one user account works with openvpn

    Scheduled Pinned Locked Moved OpenVPN
    14 Posts 3 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lgreytak
      last edited by lgreytak

      i have created a open vpn server and it works fine until i want to connect more than one user. the only user that works is the first user i used to sign into it, any user since then does not work. even if the first user is disconnected.

      all users are authenticating properly and connecting, but only the initial user can access anything (WAN and LAN).

      the end goal is to have one vpn server instance servicing several clients with access to WAN and LAN. it is most certainly a routing issue but im unfamiliar with the platform

      1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by Rico

        Share your OpenVPN settings and Firewall Rules (screenshots).

        -Rico

        L 1 Reply Last reply Reply Quote 0
        • L
          lgreytak
          last edited by

          open vpn screenshots: 2_1550009399966_Capture2.PNG 1_1550009399966_Capture1.PNG 0_1550009399964_Capture.PNG

          1 Reply Last reply Reply Quote 0
          • L
            lgreytak @Rico
            last edited by

            @rico firewall rules: 1_1550009505022_Capture1.PNG 0_1550009505022_Capture.PNG

            i do not have fail over setup or anything, primary gateway externally is Comcast, i switch to Verizon manually

            1 Reply Last reply Reply Quote 0
            • L
              lgreytak
              last edited by lgreytak

              for context: 0_1550010845496_1550009714861-capture1.png
              iv tried it with the route to Comcast gateway and it doesn't change anything. it routes the first user i used to log in just fine, cant get any other to work 0_1550009713801_Capture.PNG

              1 Reply Last reply Reply Quote 0
              • RicoR
                Rico LAYER 8 Rebel Alliance
                last edited by Rico

                In your OpenVPN Firewall tab change source to 10.10.5.0/24
                And delete your static route.

                -Rico

                1 Reply Last reply Reply Quote 0
                • L
                  lgreytak
                  last edited by

                  corrected that, still only first user works, no other user can route

                  1 Reply Last reply Reply Quote 0
                  • L
                    lgreytak
                    last edited by

                    10.10.5.2 is the connection that works and 10.10.5.3 is one of the other clients that isn't working
                    0_1550248661898_1550009714861-capture1.png

                    1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate
                      last edited by

                      Are you trying to use the same certificate/CN for all clients?

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • L
                        lgreytak
                        last edited by

                        im using the client export utility so if it doesn't create unique ones i guess i am, huh

                        1 Reply Last reply Reply Quote 0
                        • DerelictD
                          Derelict LAYER 8 Netgate
                          last edited by

                          Then you need to check that box that allows multiple users with the same CN.

                          Better to make certificates for each user.

                          Client export doesn't make them. You have to make them.

                          https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/openvpn-remote-access-server.html

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          1 Reply Last reply Reply Quote 1
                          • L
                            lgreytak
                            last edited by

                            under user manager is where i create them?
                            0_1550336027198_b702c71c-621d-4e95-8b70-b210f9560129-image.png

                            but once i make them, i have to add the cn to the config manually? i love the windows installer export

                            1 Reply Last reply Reply Quote 0
                            • DerelictD
                              Derelict LAYER 8 Netgate
                              last edited by Derelict

                              Yes. You can create the certificates there. Please see the book chapter linked.

                              No. If everything is set up properly, the client exporter will include the individual, per-user certificates.

                              Chattanooga, Tennessee, USA
                              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                              Do Not Chat For Help! NO_WAN_EGRESS(TM)

                              1 Reply Last reply Reply Quote 0
                              • L
                                lgreytak
                                last edited by

                                i had it on authentication only in the open vpn server, now users are showing up for export, you nailed it thank you so much!

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.