Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    only one user account works with openvpn

    Scheduled Pinned Locked Moved OpenVPN
    14 Posts 3 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lgreytak @Rico
      last edited by

      @rico firewall rules: 1_1550009505022_Capture1.PNG 0_1550009505022_Capture.PNG

      i do not have fail over setup or anything, primary gateway externally is Comcast, i switch to Verizon manually

      1 Reply Last reply Reply Quote 0
      • L
        lgreytak
        last edited by lgreytak

        for context: 0_1550010845496_1550009714861-capture1.png
        iv tried it with the route to Comcast gateway and it doesn't change anything. it routes the first user i used to log in just fine, cant get any other to work 0_1550009713801_Capture.PNG

        1 Reply Last reply Reply Quote 0
        • RicoR
          Rico LAYER 8 Rebel Alliance
          last edited by Rico

          In your OpenVPN Firewall tab change source to 10.10.5.0/24
          And delete your static route.

          -Rico

          1 Reply Last reply Reply Quote 0
          • L
            lgreytak
            last edited by

            corrected that, still only first user works, no other user can route

            1 Reply Last reply Reply Quote 0
            • L
              lgreytak
              last edited by

              10.10.5.2 is the connection that works and 10.10.5.3 is one of the other clients that isn't working
              0_1550248661898_1550009714861-capture1.png

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                Are you trying to use the same certificate/CN for all clients?

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • L
                  lgreytak
                  last edited by

                  im using the client export utility so if it doesn't create unique ones i guess i am, huh

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    Then you need to check that box that allows multiple users with the same CN.

                    Better to make certificates for each user.

                    Client export doesn't make them. You have to make them.

                    https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/openvpn-remote-access-server.html

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 1
                    • L
                      lgreytak
                      last edited by

                      under user manager is where i create them?
                      0_1550336027198_b702c71c-621d-4e95-8b70-b210f9560129-image.png

                      but once i make them, i have to add the cn to the config manually? i love the windows installer export

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by Derelict

                        Yes. You can create the certificates there. Please see the book chapter linked.

                        No. If everything is set up properly, the client exporter will include the individual, per-user certificates.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • L
                          lgreytak
                          last edited by

                          i had it on authentication only in the open vpn server, now users are showing up for export, you nailed it thank you so much!

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.