Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN Configuration Missteps?

    Scheduled Pinned Locked Moved OpenVPN
    8 Posts 4 Posters 977 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      wiinc1
      last edited by

      Hi -

      I have setup OpenVPN with the following configuration following https://www.youtube.com/watch?v=7rQ-Tgt3L18, but I am receiving the following error messages after connecting via Tunnelblick.

      d650f9c9-75b9-4569-8a73-f01ddc53cab0-image.png

      8dbc01b5-e3d1-41cd-bb47-3ee36d3d88af-image.png

      I used this video in the past with success. I moved and there were issues with the pfSense server that I had to reinstall the software. Now I'm getting these error messages indicating I failed in configuring the VPN.

      Anyone know how to resolve these issues?

      Thanks in advance for your help!

      1 Reply Last reply Reply Quote 0
      • W
        wiinc1
        last edited by

        Any thoughts on where I might have gone wrong?

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Waaay more info needed. 😉

          Let's see your OpenVPN server config and logs from the server end when the client connects.

          Steve

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by johnpoz

            Nothing like watching a 20 min video for something that could be done in 2 min by following the bouncing ball wizard on your own..

            192.168.3.70.0/24 as tunnel?? WTF.. What idiot would even post a video making themselves look like an idiot like that?

            2 years old... Freaking sha1, sorry couldn't get past about 4 minutes..

            What is wrong with this info?
            https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/openvpn-remote-access-server.html

            If that takes you more than 3 minutes to read through and then run the wizard yourself..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • PippinP
              Pippin
              last edited by

              With regards to Auth Digest Algorithm,
              The current recommendation from OpenVPN is SHA256, but SHA1 is not broken when used in OpenVPN because it is used as HMAC.

              I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
              Halton Arp

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by johnpoz

                My point was when you follow guides from 2 years ago, you get OLD shit... And this idiot couldn't even put in valid network for the tunnel network... How about just leaving it as default ;)

                What he should be using is NCP, and picking a GCM algo anyway..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • PippinP
                  Pippin
                  last edited by

                  The point is clear but I think you understand that mine is also ;)

                  I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
                  Halton Arp

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    Yeah.. Just because its not broken doesn't mean there is not a better more current recommended choice vs following old guides..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.