Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN | Static IP for users

    Scheduled Pinned Locked Moved OpenVPN
    10 Posts 5 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • mohkhalifaM
      mohkhalifa
      last edited by mohkhalifa

      Dear All,
      I'm trying to set a static IP for VPN users to control them through the firewall. So, I'm using Windows RADIUS and I set a static IP for the VPN users through the Active Directory then adding a policy through the Windows NPS.
      At the end the connection not established and I received an error message.
      Please note that pfSense VPN Subnet configuration is 10.10.185.0/24
      Any Help!

      User properties from windows AD:
      5a7f8b88-fa67-4796-80c4-490f0941fa9e-image.png

      Windows RADIUS:
      9bccf3d9-c216-47db-8d4d-6b4e02139f9c-image.png

      OpenVPN Connect Client:

      02137ba0-5c8c-4242-9006-fe9b7c561111-image.png

      1 Reply Last reply Reply Quote 2
      • mohkhalifaM
        mohkhalifa
        last edited by

        Dear Guys,
        Your help is highly appreciated
        Thanks,

        1 Reply Last reply Reply Quote 0
        • dotdashD
          dotdash
          last edited by

          I've never tried setting the address via NPS, but you could add a client-specific override for that user instead.

          1 Reply Last reply Reply Quote 1
          • mohkhalifaM
            mohkhalifa
            last edited by

            Dear All,
            Please note that my problem is solved and now I can authenticate OpenVPN's users via Windows RADIUS Server and also applying static IP for each user without Client Specific Overrides.
            Thanks,

            Y 1 Reply Last reply Reply Quote 0
            • dotdashD
              dotdash
              last edited by

              Care to share the details?

              1 Reply Last reply Reply Quote 0
              • A
                akuma1x
                last edited by

                This is where I do it, like @dotdash says above, in VPN -> OpenVPN -> Client Specific Overrides, in the Advanced box at the bottom of the screen.

                screenshot878343.png

                1 Reply Last reply Reply Quote 0
                • S
                  Saymon Poklad
                  last edited by

                  @akuma1x This solution has a serious problem. More details
                  https://forum.netgate.com/topic/157467/bug-openvpn-strict-user-cn-matching-is-not-case-sensitive?_=1602154685043

                  1 Reply Last reply Reply Quote 0
                  • Y
                    yanqian @mohkhalifa
                    last edited by

                    @mohkhalifa
                    You should post your findings, share with other how you solve this issue, it will benefit other users who may meet the same problem.

                    From the error message you posted, it seems that you provide wrong netmask to the openvpn client.

                    1 Reply Last reply Reply Quote 0
                    • dotdashD
                      dotdash
                      last edited by

                      Revisiting this topic, as I have seen some problems with assigning a static IP via client specific override. When working with usernames instead of cert names, users can bypass the cso if the username case doesn't match the cso (but the radius allows the connection). In a test, I found that specifying the IP address on the dial-in tab does work, provided you add the radius attribute 'Framed-IP-Netmask' to the network policy.

                      mohkhalifaM 1 Reply Last reply Reply Quote 1
                      • mohkhalifaM
                        mohkhalifa @dotdash
                        last edited by

                        Dear @dotdash
                        That's typically what I did when faced the problem.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.