Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN client specific override Error?

    Scheduled Pinned Locked Moved OpenVPN
    pfsenseclientspecificoverrideopenvpn
    13 Posts 3 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      Vlee
      last edited by

      Hello,

      I am trying to follow the guide below to configure a single multi-purpose openvpn instance.
      https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/configuring-a-single-multi-purpose-openvpn-instance.html

      However, when I create the client specific override, it looks like Pfsense deletes it after i click save? I don't see what I created under the client specific override tab.
      I then notice that there is a notification that says "PfSenseConfigurator
      pfSense is restoring the configuration /cf/conf/backup/config-1586591.xml @ 2020-04-13 16:00:41"

      Does anyone have any advice?

      • Victoria
      1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by

        I never had this error but assume you are filling special/international characters in the CSO fields?

        -Rico

        V 1 Reply Last reply Reply Quote 0
        • noplanN
          noplan
          last edited by

          screenshots of the Client Spec Override please

          1 Reply Last reply Reply Quote 0
          • V
            Vlee @Rico
            last edited by

            @Rico I'm not really sure. I am just trying to follow the guide by netgate. I am thinking what it says to paste in the Advanced section counts as special characters?

            d7b7b6ed-7cee-4362-bb38-e9ec107e32ce-image.png

            1 Reply Last reply Reply Quote 0
            • RicoR
              Rico LAYER 8 Rebel Alliance
              last edited by Rico

              "10.33.x.0" is no valid network...
              You can use the IPv4 Tunnel Network box in CSO to push the route(s) anyway which would be the better solution.

              -Rico

              V 1 Reply Last reply Reply Quote 1
              • V
                Vlee @Rico
                last edited by

                @Rico Oh! I'll look into the IPv4 Tunnel Network box.
                I did change the route to push"route 10.33.127.0 255.255.255.0" but got the same outcome.

                Thank you.

                1 Reply Last reply Reply Quote 0
                • noplanN
                  noplan
                  last edited by

                  the only IPs you have to set in openVPN Server are here (and afaik no where else)

                  413ca79f-87d0-4dde-ae20-3dc1fd2cf918-grafik.png

                  ec3b8b0c-cc82-47ed-ba44-84e0db7de29f-grafik.png

                  e4c202cd-0704-4dcd-8d44-c8fc020d05f4-grafik.png

                  show the config of your setting openVPN (screenShot) and of client specific override

                  V 1 Reply Last reply Reply Quote 0
                  • V
                    Vlee @noplan
                    last edited by

                    @noplan Ah maybe that's my issue. I haven't set a DNS or NTP Server
                    This is what i Have as my ipv4 tunnel network 289479d5-54a1-4188-977c-206583e3714c-image.png

                    1 Reply Last reply Reply Quote 0
                    • noplanN
                      noplan
                      last edited by

                      dns is nice
                      ntp not nescessary

                      my point was that you do not need more IPs than those

                      out of the blue is your openVPN tunnel workin without client spec override ?

                      what is workin and what is the issue ?

                      V 1 Reply Last reply Reply Quote 0
                      • V
                        Vlee @noplan
                        last edited by

                        @noplan
                        Thanks for the info.
                        I've never worked with client spec override. I am trying to set it up.
                        The issue is that when I go to save what I enter it seems to go missing.
                        If I go back to look at the changes I save, it is empty under the Client Specific Overrides tab.
                        Is that normal?

                        0e7095ba-ace0-49c2-801f-9688bf8637e1-image.png

                        1 Reply Last reply Reply Quote 0
                        • noplanN
                          noplan
                          last edited by

                          only things to choose n use for qnD
                          pre requirements (ad user and cert are all done and a client can connect and openVPN is wrokin)

                          7abb5926-49da-4183-85ce-3aec6a1d7006-grafik.png
                          6f8f681e-a835-4c53-87c7-68662da8f272-grafik.png

                          put here the IP for the override in CIDR format
                          d2c47ebc-42af-40eb-bc57-dfd265a442e6-grafik.png

                          optional depends on your settings
                          10105180-0135-4ec5-ae10-80484138a984-grafik.png

                          e44b276d-62ff-41b2-a77d-ad3e0aa1526f-grafik.png
                          0a643083-6545-4f0b-900d-cd05387affc4-grafik.png

                          if you believe me that i#m right if not not nescessary to fill some in
                          bb81636e-43df-4169-96db-8172cea7a50a-grafik.png

                          1 Reply Last reply Reply Quote 0
                          • RicoR
                            Rico LAYER 8 Rebel Alliance
                            last edited by Rico

                            Whops, sorry to say I told you the wrong CSO box (already had my 10 hrs workday ;-)). Correct is IPv4 Local Network/s and NOT IPv4 Tunnel Network.
                            But mostly you would define the networks/routes to push in the Server configuration.

                            -Rico

                            1 Reply Last reply Reply Quote 0
                            • noplanN
                              noplan
                              last edited by

                              @Rico
                              word! i do not need to unserstand why i would do this ;)
                              CSO local networks but here in ausrtia a lot of things are possible ;)

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.