Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN Inter-client communication option doesn't work

    Scheduled Pinned Locked Moved OpenVPN
    11 Posts 3 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jcorreajr
      last edited by

      The Inter-client communication option in the OpenVPN server configuration does not function properly. The XML file shows yes if it's checked, but does not add the line client-to-client to the server config file at /var/etc/openvpn/server1.conf

      Version: 2.4.4p1 and 2.4.4p3

      Has anyone else noticed this problem?

      1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by

        I played around and it works for me in all Remote Access Modes:
        Remote Access (SSL/TLS)
        Remote Access (User Auth)
        Remote Access (SSL/TLS + User Auth)

        It is NOT working in Peer to Peer (SSL/TLS) Mode.
        This looks more like a GUI Bug to me, I don't think inter-client should be there in this mode.

        Which mode are you running?

        -Rico

        1 Reply Last reply Reply Quote 0
        • J
          jcorreajr
          last edited by

          Hello,
          I am using the mode: "Peer to Peer (SSL / TLS)"
          According to the manual: https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/configuring-a-site-to-site-pki-ssl-openvpn-instance.html

          At times I need to access between the remote points, so I enabled the client-to-cient option and I noticed that it did not work.

          1 Reply Last reply Reply Quote 0
          • RicoR
            Rico LAYER 8 Rebel Alliance
            last edited by

            You need to set your local and remote networks in OpenVPN and add Firewall Rules.

            -Rico

            1 Reply Last reply Reply Quote 1
            • PippinP
              Pippin
              last edited by

              Yes like that ^^^ and do not enable client-to-client...

              I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
              Halton Arp

              1 Reply Last reply Reply Quote 1
              • J
                jcorreajr
                last edited by

                OK, I'm going to study the implications of changing to the "Remote Access (SSL / TLS)" model by applying the client-to-client configuration on it

                1 Reply Last reply Reply Quote 0
                • RicoR
                  Rico LAYER 8 Rebel Alliance
                  last edited by

                  Well you should use Peer to Peer if you want to connect two Sites.
                  And you don‘t need the inter-client option there.

                  -Rico

                  1 Reply Last reply Reply Quote 1
                  • PippinP
                    Pippin
                    last edited by Pippin

                    Just for info, pfSense will not see the OpenVPN client packets when Inter-client communication is enabled making it impossible to filter.
                    https://community.openvpn.net/openvpn/wiki/Topology
                    OpenVPN traffic flow

                    I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
                    Halton Arp

                    1 Reply Last reply Reply Quote 2
                    • J
                      jcorreajr
                      last edited by

                      Thanks to all for your help

                      1 Reply Last reply Reply Quote 0
                      • RicoR
                        Rico LAYER 8 Rebel Alliance
                        last edited by

                        Nice overview @Pippin thanks.

                        -Rico

                        1 Reply Last reply Reply Quote 0
                        • PippinP
                          Pippin
                          last edited by

                          Welcome :)

                          I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
                          Halton Arp

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.