Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Recent
    Log in to post
    Load new posts
    • All Topics
    • New Topics
    • Watched Topics
    • Unreplied Topics
    • All categories
    • All tags
    • F

      Site-to-Site ovpn setup has limited connectivity

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      3
      0 Votes
      3 Posts
      395 Views
      F

      SOLVED: This is possibly a bug. In the client specific overrides, the IPV4 Remote Newtork setting doesn't have the desired effect. When I removed that setting and added iroute 10.20.120.0 255.255.255.0 to advanced settings, it began working bidirectionally, between all nodes.

    • R

      OpenVPN Client Deployment Options

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      1
      0 Votes
      1 Posts
      180 Views
      No one has replied
    • N

      OpenVPN IPV6 Question

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      1
      0 Votes
      1 Posts
      159 Views
      No one has replied
    • A

      Can not establish connection to OPENVPN server

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      4
      0 Votes
      4 Posts
      455 Views
      GertjanG

      @abonent1978

      If the only VPN config present contains :

      remote 171.x.x.x 1199

      Then where does "92.113.146.1:1194" come from ?

      What / who is the client VPN ?

    • S

      Slow VPN speed on OpenVPN through PFSense

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      4
      0 Votes
      4 Posts
      687 Views
      P

      Several things will affect performance. VPN will always be slower due to the encryption-decryption processes.

      What else is the VM host doing ? Have you tried other encrytpion algorythms ? What CPU is the client using ? Perhaps run PfSense on it's own hardware ?
    • I

      Unable to connect to my server

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      2
      0 Votes
      2 Posts
      270 Views
      V

      @IT-META
      I guess, your "TLS Key Usage Mode" is wrong.
      You can either configure it for authentication only or auth + control channel encryption.

      Check your server settings and configure the client accordingly.

    • X

      OpenVPN Auth failure

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      2
      0 Votes
      2 Posts
      320 Views
      X

      I found an error in the RADIUS server setup that has fixed this issue.

    • C

      OpenVPN wizard WAN rule allows outside access to the administrative WebGUI

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      3
      0 Votes
      3 Posts
      516 Views
      C

      @patient0 Thanks much, I'll check it out!

    • Z

      Issue Killing Specific OpenVPN Client Connection from Dashboard (PHP Fatal Error)

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      1
      0 Votes
      1 Posts
      152 Views
      No one has replied
    • V

      Instability and High Resource Usage on pfSense 24.11 with OpenVPN + OSPF (Site-to-Site Failover)

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      3
      0 Votes
      3 Posts
      363 Views
      L

      For reference, the site-to-site environment we had set up between the two locations was based on this official Netgate configuration:
      šŸ‘‰ [OpenVPN + OSPF Site-to-Site Setup]

      This is the exact topology and integration model that was implemented, that worked flawlessly until the upgrade to 24.11, which further supports the conclusion that the issue lies with the OpenVPN tunnel performance rather than OSPF itself.

    • P

      Endpoint address family (IPv6) is incompatible with transport protocol (udp4)

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      7
      0 Votes
      7 Posts
      961 Views
      JKnottJ

      @pietsnot56 said in Endpoint address family (IPv6) is incompatible with transport protocol (udp4):

      Any idea what's wrong?

      Many cell networks are now IPv6 only. On Android devices, 464XLAT is used to connect to IPv4 only sites over an IPv6 only network. iPhones use something similar, but I don't know the details. Perhaps there's some issue there. My phone gets the IPv4 address 192.0.0.4, which is reserved for 464XLAT, as well as a global IPv6 address.

      I have pfSense configured to allow openVPN to use either IPv4 or IPv6 to connect. Do you have IPv6 available from Telenet?

      BTW, Telenet used to be an X.25 packet switched network back in the dark ages. The company I used to work for provided Telenet in Canada and I maintained part of that system.

    • K

      Slow throughput when using Windows OpenVPN clients vs Linux

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      1
      0 Votes
      1 Posts
      162 Views
      No one has replied
    • L

      Accesssing a local subnet defined as an alias over LAN from OpenVPN

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      1
      0 Votes
      1 Posts
      165 Views
      No one has replied
    • V

      Upgrade 2.6 to 2.7 Open VPN broken

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      5
      0 Votes
      5 Posts
      639 Views
      V

      @stephenw10 Yes you are correct, I misunderstood myself. After my box crashed doing the 2.6.0 to 2.7.0 upgrade and eventually after getting 2.7.0 to work, I compared both xml backup files and only saw differences in time stamps, but now realise it's the import of updated packages that caused my problem.

      I'm running ZFS and will look at taking an image snap once I work out how to get from Pfsense to FreeBSD, out and back via a USB3 port. That suggests I need an external monitor, keyboard, and mouse on the box, unless it can be done through Pfsense GUI, but that won't work for recovery if the GUI has crashed. I've met these situations before and an image snap can only be trusted to work if you've actually used it successfully to recover. In the PC world I've trusted and used Acronis for years. Thanks for the link. I've always created bootable flash sticks and created matching config XMLs. Once the box crashes, I'm offline with no internet access to download anything or get help asking questions. I still keep an ISP Thomson box handy just in case.

      Thanks for your help - regards - Vox

    • G

      SiteToSite only oneway

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      5
      0 Votes
      5 Posts
      594 Views
      G

      Solved, since i'm using azure vm i'd to add route on azure portal.

      Thanks to all

    • W

      Users are unable to authenticate after renewal of CA certificate of domain controller

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      1
      0 Votes
      1 Posts
      192 Views
      No one has replied
    • B

      Open VPN Remote Access Routing to specific TLS Client needs special CSO treatment. (2.7.2)

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      2
      0 Votes
      2 Posts
      308 Views
      B

      Update:

      I had the same issue today, configuring another client with the same topology.
      This time i had another pfsense 2.7.2 needed the extra routing on CSO when i created a remote access open VPN Server on the same pfSense.

      I lost access suddenly during configuration, and then i had to use again Client specific override for the VPN Tunnel in order to communicate again. Based on above, it seems that Open VPN inter-routing acting strangely.

      Is this a miss-configuration from my side, and i should always have that extra routing for the remote access tunnel ? or is a bug in the OpenVPN implementation on pfSense ?? Still i'm wondering why some instances working and some not.

      Please, awaiting for any comments and if someone faced that again in the past.

    • M

      NAT from internet host through WAN to VPN connected host on specific tcp port

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      6
      0 Votes
      6 Posts
      745 Views
      V

      @Martek said in NAT from internet host through WAN to VPN connected host on specific tcp port:

      My posibility is to use "Client Specific Overrides" to adjust that end of the VPN tunnel.

      Yeah, the CSO is needed on the server to route the traffic to the proper client. But it doesn't do anything on the client side.

      However using "Client Specific Overrides" with "Redirect Gateway: Force all client generated traffic through the tunnel" to be set, doesn't change the result.

      I'd expect, that it would work with this option, presumed the route on the client is really added.
      This would route any upstream traffic from the client over the VPN, however, but not only responses on the forwarded requests. Is this, what you want?

      If so the outbound NAT rule on WAN for LAN2, you mentioned above, is needed to get internet access.

      For testing the routing, on pfSense try to ping the host in LAN2 from the LAN1 IP. Ensure that the firewall of the host itself doesn't block access from outside.
      Also check if the upstream traffic is routed over the VPN by accessing whatismyipaddress.com or something else showing you source IP.

    • F

      monitoring certificate & CRL expirations

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      1
      0 Votes
      1 Posts
      180 Views
      No one has replied
    • P

      Can connect to OVPN Server and that's about it

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN ovpn server firewall log
      15
      0 Votes
      15 Posts
      1k Views
      GertjanG

      @pfsblah said in Can connect to OVPN Server and that's about it:

      I can't give thumbs up

      Gave you one šŸ‘