Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [Resolved] How do I make Client Overrides work?

    OpenVPN
    2
    8
    918
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      Dunno
      last edited by Dunno

      How do I make Client Overrides work? I cannot make them work at all. The client is able to connect to the server but I cannot make traffic-through a client-specific. I added a client override with the same CN as the client and ticked the button "force all client generated traffic through the tunnel" and reconnected as a client.

      If I force it from the server settings it works but I don't want to force nor allow it for the other clients.

      Any hints?

      N 1 Reply Last reply Reply Quote 0
      • N
        netblues @Dunno
        last edited by

        @Dunno Make sure the common name is typed exactly as in the certificate. Including capitalisation. dots etc.

        What you are trying to do has been tested and works just as per your configuration

        D 1 Reply Last reply Reply Quote 1
        • D
          Dunno @netblues
          last edited by

          @netblues Huh. Thank you for confirming. You led me to try different things. The solution is that the OpenVPN disconnect is not enough. You have to close the OpenVPN client completely and start it again in order to get that configuration. Even state reset did not the trick if OpenVPN is kept open after disconnecting the existing connection. It seems that OpenVPN stores some cache or memory about the config.

          N 1 Reply Last reply Reply Quote 0
          • N
            netblues @Dunno
            last edited by netblues

            @Dunno Actually is the client who makes the routing decisions, so the server just pushes settings to the client. If the connection is not fully renegotiated, client route settings wont be upgraded.
            Clearing states wouldn'n have any effect too.

            So, no caching, you just have to triger settings push. (by fully disconnecting, client side.)

            D 1 Reply Last reply Reply Quote 0
            • D
              Dunno @netblues
              last edited by

              @netblues If I right-click tray icon of OpenVPN doesn't that fully disconnect?

              N 1 Reply Last reply Reply Quote 0
              • N
                netblues @Dunno
                last edited by

                @Dunno If you select disconnect, yes, if you just select reconnect, its a different story.

                D 1 Reply Last reply Reply Quote 0
                • D
                  Dunno @netblues
                  last edited by

                  @netblues I'm sure I pressed disconnect. Settings didn't apply. Only exiting helped.

                  1 Reply Last reply Reply Quote 1
                  • N
                    netblues
                    last edited by

                    In any case, its client side, pf can't do anything about it.

                    1 Reply Last reply Reply Quote 1
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.