Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFsense 2.5 RC OpenVPN/ExpressVPN problem

    Scheduled Pinned Locked Moved General pfSense Questions
    vpnopen vpnexpressvpnnetworkingproblems
    43 Posts 9 Posters 10.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      LayerThree @JairoAV25
      last edited by

      @jairoav25 I understand this but I will stay with PfSense and try to figure this Problem out xD

      J 1 Reply Last reply Reply Quote 1
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Mmm, this seems almost certainly to be a config mismatch between the OpenVPN 2.5 client in pfSense 2.5 (confusingly!) and the OpenVPN 2.4 server you're trying to connect to.

        The first thing I would try is leaving NCP enabled and adding AES-256-CBC to the list of ciphers.

        Also set compression to 'Omit prefernce' since you can see in the logs the server is pushing comp-lzo no but you have it set to adaptive.

        Steve

        1 Reply Last reply Reply Quote 0
        • A
          applesalwaysred @LayerThree
          last edited by

          @layerthree Yes.

          1 Reply Last reply Reply Quote 0
          • J
            JairoAV25 @LayerThree
            last edited by

            @layerthree

            OpenWRT didn't work. The solution in my case was to install OpnSense. Check my response here

            1 Reply Last reply Reply Quote 1
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Anyone seeing a problem with the expressvpn certificate?

              Just seen where it looks like they are issuing a 50 year cert that is overrunning a counter and hence shows as expired.

              Steve

              stephenw10S 1 Reply Last reply Reply Quote 1
              • O
                OpenResty
                last edited by OpenResty

                Hey, I could be wrong but I think its something to do with the NAT.
                I personnaly would try going over to NordVPN's SetUp for pfsense 2.5 & try that . Try loading both tutorials next to each other in browser to compare.
                Now In the beginning of tutorial try to Load cetificates the expressvpn way instead of Nords, But then from there follow Nordvpn for the rest of the setup. Also Make Sure when you add Expressvpn to the NAT as described that you add it to the top of the Mappings List & not at the bottom.
                Maybe having a look at Nords Tutorial may give some Clues. Also make sure you reboot pfsense after setup as it may still look like its not working but hopefully will after a reboot.
                I dont think theres any harm in trying but make sure to reboot if it looks to not work after.
                If it will work for NordVPN 2.5 then it may work for Express. XXXX

                A 1 Reply Last reply Reply Quote 1
                • A
                  applesalwaysred @OpenResty
                  last edited by applesalwaysred

                  @openresty Just got an update from support. Removed the option "Don't pull routes" which is mentioned in their guide. I now have an encrypted connection.

                  L 1 Reply Last reply Reply Quote 2
                  • L
                    LayerThree @applesalwaysred
                    last edited by

                    @applesalwaysred so u did everything like in the guide except this the "Dont pull routes" and it works?

                    If that's true, then I will update soon!

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator @stephenw10
                      last edited by

                      @stephenw10 said in PFsense 2.5 RC OpenVPN/ExpressVPN problem:

                      Anyone seeing a problem with the expressvpn certificate?

                      Just seen where it looks like they are issuing a 50 year cert that is overrunning a counter and hence shows as expired.

                      Yeah if you're using the SG-3100 (or SG-1000) you might hit that. There is a patch for it now:
                      https://redmine.pfsense.org/issues/11504

                      Steve

                      1 Reply Last reply Reply Quote 0
                      • L
                        LayerThree
                        last edited by

                        So the "Don't pull routes" solved the whole problem.

                        Follow the guide, except this step and then restart ur machine. After this everything works.

                        Thank you for ur help!

                        B 1 Reply Last reply Reply Quote 1
                        • B
                          bcruze @LayerThree
                          last edited by bcruze

                          @layerthree said in PFsense 2.5 RC OpenVPN/ExpressVPN problem:

                          So the "Don't pull routes" solved the whole problem.

                          Follow the guide, except this step and then restart ur machine. After this everything works.

                          Thank you for ur help!

                          I posted in the other thread. I just reset up my provider that wasn't working

                          it connected. but if I restart the tunnel. traffic stop passing again

                          you?

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            I would always set 'don't pull routes' personally. Otherwise you're at the mercy of whatever they want to send you, which is usually a new default route.
                            However if you don't pull routes from them you need to policy route the traffic you want via the VPN gateway.

                            Steve

                            1 Reply Last reply Reply Quote 2
                            • T
                              trikki69
                              last edited by trikki69

                              Apologies for resurrecting this thread 5 months after the last post but I'm hoping the solution I found helps someone else out with pfsense and ExpressVPN problems.

                              I've been having really big problems trying to get ExpressVPN working on pfsense - took me about 6 hrs of troubleshooting yesterday.

                              First, I set the VPN gateways to "unmonitored" in the routing section of pfsense - don't think it made any differece but the gateways now report as green "up - unmonitored" instead of red "offline - 100% Packet loss"

                              I thought I'd found the answer in this post about unchecking "don't pull routes" but as per @stephenw10 commented, I was getting a new default route pushed to me, all of my clients where getting pushed out of the VPN interface which is not what I wanted.
                              I tried adding my own default route but as soon as the VPN service stopped and started again the VPN pushed default route was back again and all of my clients were being sent out over the VPN again.

                              I finally added this to my advanced custom options within the OpenVPN client setup:
                              ;pull-filter ignore redirect-gateway;

                              I don't get any problems with VPN pushed default routes now even when the VPN services are restarted.
                              Hope this helps someone in the future. :)

                              noplanN 1 Reply Last reply Reply Quote 0
                              • noplanN
                                noplan @trikki69
                                last edited by

                                @trikki69 said in PFsense 2.5 RC OpenVPN/ExpressVPN problem:

                                so your problem is now solved with this

                                added this to my advanced custom options within the OpenVPN client setup:
                                ;pull-filter ignore redirect-gateway;

                                brNP

                                T 1 Reply Last reply Reply Quote 0
                                • T
                                  trikki69 @noplan
                                  last edited by

                                  @noplan said in PFsense 2.5 RC OpenVPN/ExpressVPN problem:

                                  @trikki69 said in PFsense 2.5 RC OpenVPN/ExpressVPN problem:

                                  so your problem is now solved with this

                                  added this to my advanced custom options within the OpenVPN client setup:
                                  ;pull-filter ignore redirect-gateway;

                                  brNP

                                  Yep - works great now, no thanks to ExpressVPN support.

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.