• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

OpenVPN | Static IP for users

OpenVPN
5
10
1.5k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    mohkhalifa
    last edited by mohkhalifa Oct 4, 2020, 2:47 PM Oct 4, 2020, 2:45 PM

    Dear All,
    I'm trying to set a static IP for VPN users to control them through the firewall. So, I'm using Windows RADIUS and I set a static IP for the VPN users through the Active Directory then adding a policy through the Windows NPS.
    At the end the connection not established and I received an error message.
    Please note that pfSense VPN Subnet configuration is 10.10.185.0/24
    Any Help!

    User properties from windows AD:
    login-to-view

    Windows RADIUS:
    login-to-view

    OpenVPN Connect Client:

    login-to-view

    1 Reply Last reply Reply Quote 2
    • M
      mohkhalifa
      last edited by Oct 5, 2020, 9:36 PM

      Dear Guys,
      Your help is highly appreciated
      Thanks,

      1 Reply Last reply Reply Quote 0
      • D
        dotdash
        last edited by Oct 5, 2020, 9:47 PM

        I've never tried setting the address via NPS, but you could add a client-specific override for that user instead.

        1 Reply Last reply Reply Quote 1
        • M
          mohkhalifa
          last edited by Oct 6, 2020, 6:18 PM

          Dear All,
          Please note that my problem is solved and now I can authenticate OpenVPN's users via Windows RADIUS Server and also applying static IP for each user without Client Specific Overrides.
          Thanks,

          Y 1 Reply Last reply Oct 15, 2020, 2:45 PM Reply Quote 0
          • D
            dotdash
            last edited by Oct 6, 2020, 6:23 PM

            Care to share the details?

            1 Reply Last reply Reply Quote 0
            • A
              akuma1x
              last edited by Oct 6, 2020, 6:30 PM

              This is where I do it, like @dotdash says above, in VPN -> OpenVPN -> Client Specific Overrides, in the Advanced box at the bottom of the screen.

              login-to-view

              1 Reply Last reply Reply Quote 0
              • S
                Saymon Poklad
                last edited by Oct 8, 2020, 11:01 AM

                @akuma1x This solution has a serious problem. More details
                https://forum.netgate.com/topic/157467/bug-openvpn-strict-user-cn-matching-is-not-case-sensitive?_=1602154685043

                1 Reply Last reply Reply Quote 0
                • Y
                  yanqian @mohkhalifa
                  last edited by Oct 15, 2020, 2:45 PM

                  @mohkhalifa
                  You should post your findings, share with other how you solve this issue, it will benefit other users who may meet the same problem.

                  From the error message you posted, it seems that you provide wrong netmask to the openvpn client.

                  1 Reply Last reply Reply Quote 0
                  • D
                    dotdash
                    last edited by Oct 30, 2020, 10:08 PM

                    Revisiting this topic, as I have seen some problems with assigning a static IP via client specific override. When working with usernames instead of cert names, users can bypass the cso if the username case doesn't match the cso (but the radius allows the connection). In a test, I found that specifying the IP address on the dial-in tab does work, provided you add the radius attribute 'Framed-IP-Netmask' to the network policy.

                    M 1 Reply Last reply Oct 31, 2020, 1:16 AM Reply Quote 1
                    • M
                      mohkhalifa @dotdash
                      last edited by Oct 31, 2020, 1:16 AM

                      Dear @dotdash
                      That's typically what I did when faced the problem.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.