Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Setup pfSense as a VPN server

    Scheduled Pinned Locked Moved OpenVPN
    9 Posts 2 Posters 919 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      paps_line
      last edited by

      Re: Connect VPN Clients to Local network behind other client...

      Hi everyone, I'm a beginner with psfense , i use a mikrotik as a main gateway and i want to set up a pfsense as vpn server (using a openvpn), i already configured a kind of ways a pfsense (with just one interface or two ) but doesn't work. When i use two interface (wan and lan) i just can connect a Lan that belong a pfsense, and can't connect on my main LAN
      My structure :
      Internet -> mikrotik-> LAN ->WANpfsense ->pfsense()-> LAN pfsense(but i don't use this)

      Please someone can help me?

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        Why don't you replace the mikrotik with pfSense? It much easier to run a VPN server on the edge router than behind in the LAN.

        P 1 Reply Last reply Reply Quote 0
        • P
          paps_line @viragomann
          last edited by

          @viragomann
          hi, i already use that mikrotik a long time ago it' a CCR model, somewhat expensive to be desabled, so i want just separate some services, and i also think that part of the firewall was easier to manage.

          1 Reply Last reply Reply Quote 0
          • V
            viragomann
            last edited by

            Running the VPN server behind the router needs more configuration work. However, basically it's doable.

            Is the a possibility to connect pfSense to the mikrotik on a separate network aside from LAN? It could be a VLAN over your LAN, but that would enable a better routing.

            P 1 Reply Last reply Reply Quote 0
            • P
              paps_line @viragomann
              last edited by

              yes, there is a possibility. I'll try to do that . Can I set up the pfsense with just interface WAN to do that ?

              1 Reply Last reply Reply Quote 0
              • V
                viragomann
                last edited by

                You only need one interface on pfSense, that can be WAN or LAN. If you use WAN you have to uncheck "Block private networks" in the interface settings, otherwise you can't access the OpenVPN server.

                V 1 Reply Last reply Reply Quote 0
                • V
                  viragomann
                  last edited by

                  On the mikrotik forward the OpenVPN packets to pfSense.
                  Further set a static route for the VPN tunnel network pointing to pfSense.

                  On pfSense just set the mikrotik as default gateway.

                  1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @viragomann
                    last edited by

                    @viragomann said in Setup pfSense as a VPN server:

                    You only need one interface on pfSense, that can be WAN or LAN. If you use WAN you have to uncheck "Block private networks" in the interface settings, otherwise you can't access the OpenVPN server.

                    Edit:
                    I'd prefer to use the LAN here, cause it's pre-configured to access the WebGUI.

                    P 1 Reply Last reply Reply Quote 0
                    • P
                      paps_line @viragomann
                      last edited by

                      hi, thanks só much for help, i was trying create without create vlan first and i realy don't know wy it doesn't worked. So, I create a vlan separated and did the same configuration as before using just WAN and it works, little bit slow but works, thanks

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.