Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [Solved] Cannot get OpenVPN server to mask Client Public IP

    OpenVPN
    2
    7
    2.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      testcb00
      last edited by stephenw10

      Hi everyone, I am newbie to this forum. Current I have set up a pfSense Router based on this guide https://nguvu.org/pfsense/pfsense-baseline-setup/

      I ignore the DNS and NTP server settings as I don't own these server.

      Now, I want to try the OpenVPN server features. I follow this guide https://chrislazari.com/pfsense-setting-up-openvpn-on-pfsense-2-4/ and make some adjustment to get this configuration.

      alt text

      Using this configuration, I am able to connect to the OpenVPN Server (tried Android Phone or iPad in Wi-Fi or Cellular connection) and connect to my Intranet, but the outgoing (Internet) of Client is still using the Client IP (my pfSense Router and Wi-Fi Router are in two different public IP).

      I tried to add Outbound like the below photo but no luck.

      alt text

      May you give any suggestion?

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @testcb00
        last edited by

        @testcb00
        Check "Redirect gateway" in the server settings.

        T 1 Reply Last reply Reply Quote 0
        • T
          testcb00 @viragomann
          last edited by

          @viragomann
          I just tried, in this configuration, I cannot access Intranet and Internet in the Client...

          Seems the DNS is blocked?
          alt text

          The OpenVPN log is here
          alt text

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @testcb00
            last edited by

            @testcb00
            Seems the traffic from the VPN is not allowed on the VPN server. Check the rule on the OpenVPN interface.

            Regarding the mtu, this might be an aftereffect of using TCP mode. The connection should work anyway, but possibly you can get it solved by setting individual mtu options.

            T 1 Reply Last reply Reply Quote 1
            • T
              testcb00 @viragomann
              last edited by

              @viragomann said in Cannot get OpenVPN server to mask Client Public IP:

              @testcb00
              Seems the traffic from the VPN is not allowed on the VPN server. Check the rule on the OpenVPN interface.

              Regarding the mtu, this might be an aftereffect of using TCP mode. The connection should work anyway, but possibly you can get it solved by setting individual mtu options.

              Thanks viragomann. I forget to add the rules. I tried to add rules before I post to forum but the rules didn't work at that time. Is there any delay to apply these rules? or the client DNS is "broken" so that I have to wait for DNS cache expired?

              alt text

              Now I can mask the public IP of the client but I cannot access Intranet. Is there any solution of accessing Intranet and mask public IP at the same time?

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @testcb00
                last edited by

                @testcb00 said in Cannot get OpenVPN server to mask Client Public IP:

                Now I can mask the public IP of the client but I cannot access Intranet.

                Did you also try accessing by IP address?

                These rule may pass all traffic now, presumed OPT4 is the interface you've assigned to the OpenVPN instance.
                Pass rules are applied immediately.
                What do get now? Something in the logs?

                Consider that by default network computers may block access from outside their own subnet. So you might have to open their firewall.

                T 1 Reply Last reply Reply Quote 1
                • T
                  testcb00 @viragomann
                  last edited by

                  @viragomann All done. Misunderstanding on my Intranet Application state. You're right, using Intranet IP can access my Application.

                  Thank you very much, viragomann. You saved my days.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.