<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenVPN client static ip CSO not working]]></title><description><![CDATA[<p dir="auto">2.3.1-RELEASE-p1 (amd64)<br />
built on Wed May 25 14:53:06 CDT 2016<br />
FreeBSD 10.3-RELEASE-p3</p>
<p dir="auto">I'm using OpenVPN with LDAP authentication.<br />
my network design uses two internal networks<br />
192.168.248.x/24 network<br />
10.0.0.4/30 network</p>
<p dir="auto">10.2.0.0/24 network for OpenVPN clients<br />
Connection using Windows 7 client (OpenVPN client) works fine. Client traffic is tunneled across the vpn.</p>
<p dir="auto">I' trying to set static ip to remote users based on X.509 common name to restrict network access based on source IP address.<br />
If I set a diferent network (10.3.0.0/24 or 10.3.0.0/30) on CSO to a User, connection is not working<br />
If I set same network on CSO 10.2.0.0/24 connection is working, but client gets ip address 10.2.0.0 and DHCP server informed to client is 10.2.0.254. If I ping from OpenVPN server side to Windows client it works. I can also browse SMB resources.<br />
If I try to set static IP using advanced option it does not work and ip 10.2.0.0 is set to windows client:<br />
ifconfig-push 10.2.0.240 10.2.0.1;</p>
<p dir="auto">this is my OpenVPN Windows client connection log:<br />
Thu Jun 16 18:13:27 2016 SIGHUP[hard,] received, process restarting<br />
Thu Jun 16 18:13:27 2016 OpenVPN 2.3.11 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [PKCS11] [IPv6] built on May 10 2016<br />
Thu Jun 16 18:13:27 2016 Windows version 6.1 (Windows 7) 64bit<br />
Thu Jun 16 18:13:27 2016 library versions: OpenSSL 1.0.1t  3 May 2016, LZO 2.09<br />
Thu Jun 16 18:13:29 2016 Control Channel Authentication: using 'pfSense-udp-1194-tls.key' as a OpenVPN static key file<br />
Thu Jun 16 18:13:29 2016 UDPv4 link local (bound): [undef]<br />
Thu Jun 16 18:13:29 2016 UDPv4 link remote: [AF_INET]WAN_IP_ADDRESS:1194<br />
Thu Jun 16 18:13:29 2016 [FQDN_ADDRESS] Peer Connection Initiated with [AF_INET]WAN_IP_ADDRESS:1194<br />
Thu Jun 16 18:13:31 2016 do_ifconfig, tt-&gt;ipv6=0, tt-&gt;did_ifconfig_ipv6_setup=0<br />
Thu Jun 16 18:13:31 2016 open_tun, tt-&gt;ipv6=0<br />
Thu Jun 16 18:13:31 2016 TAP-WIN32 device [Conexión de área local 3] opened: \.\Global{247D5993-18E4-4F2C-A5E9-F5ABF62FFF08}.tap<br />
Thu Jun 16 18:13:31 2016 Set TAP-Windows TUN subnet mode network/local/netmask = 10.2.0.0/10.2.0.0/255.255.255.0 [SUCCEEDED]<br />
Thu Jun 16 18:13:31 2016 Notified TAP-Windows driver to set a DHCP IP/netmask of 10.2.0.0/255.255.255.0 on interface {247D5993-18E4-4F2C-A5E9-F5ABF62FFF08} [DHCP-serv: 10.2.0.254, lease-time: 31536000]<br />
Thu Jun 16 18:13:31 2016 Successful ARP Flush on interface [32] {247D5993-18E4-4F2C-A5E9-F5ABF62FFF08}<br />
Thu Jun 16 18:13:36 2016 Initialization Sequence Completed</p>
<p dir="auto">Thanks in advance.</p>
]]></description><link>https://forum.netgate.com/topic/101602/openvpn-client-static-ip-cso-not-working</link><generator>RSS for Node</generator><lastBuildDate>Thu, 11 Jun 2026 22:12:14 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/101602.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 16 Jun 2016 16:18:05 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to OpenVPN client static ip CSO not working on Sun, 19 Jun 2016 09:56:29 GMT]]></title><description><![CDATA[<p dir="auto">ok, thanx, but i decided degrade to 2.2.4 version (stable).</p>
]]></description><link>https://forum.netgate.com/post/632598</link><guid isPermaLink="true">https://forum.netgate.com/post/632598</guid><dc:creator><![CDATA[Electricshock]]></dc:creator><pubDate>Sun, 19 Jun 2016 09:56:29 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN client static ip CSO not working on Sun, 19 Jun 2016 07:14:50 GMT]]></title><description><![CDATA[<p dir="auto">Well, I've found how to make it work, but not in subnet mode.</p>
<p dir="auto">I've set openVPN Server config topology in net/30 mode. I've used a 10.x.x.x/16 subnet.<br />
Later, in CSO Tunnel Network use a /30 per user.<br />
10.x.x.0/30, 10.x.x.4/30…10.x.x.252/30</p>
<p dir="auto">Client wil use second usable address in subnet, router uses firstone usable. I'm loosing 3 address for every client to use, but using 10.x.x.x/16 you can define more tan 16.000 remote users.</p>
<p dir="auto">Later, with firewall rules you can tuneup user Access based on their ip address</p>
<p dir="auto">hope it helps.</p>
]]></description><link>https://forum.netgate.com/post/632590</link><guid isPermaLink="true">https://forum.netgate.com/post/632590</guid><dc:creator><![CDATA[rcuello]]></dc:creator><pubDate>Sun, 19 Jun 2016 07:14:50 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN client static ip CSO not working on Sat, 18 Jun 2016 05:07:04 GMT]]></title><description><![CDATA[<p dir="auto">Hi man!<br />
Same problem…dunno how 2 fix it.</p>
]]></description><link>https://forum.netgate.com/post/632473</link><guid isPermaLink="true">https://forum.netgate.com/post/632473</guid><dc:creator><![CDATA[Electricshock]]></dc:creator><pubDate>Sat, 18 Jun 2016 05:07:04 GMT</pubDate></item></channel></rss>