<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenVPN: two clients in a gateway group]]></title><description><![CDATA[<p dir="auto">I got my VPN working. How do I set-up  for two clients in a gateway group? Any good reference links?</p>
]]></description><link>https://forum.netgate.com/topic/113839/openvpn-two-clients-in-a-gateway-group</link><generator>RSS for Node</generator><lastBuildDate>Mon, 13 Apr 2026 06:00:01 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/113839.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 30 Mar 2017 23:48:51 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to OpenVPN: two clients in a gateway group on Sat, 01 Apr 2017 22:32:52 GMT]]></title><description><![CDATA[<p dir="auto">Much better. I am online now. Thank you. I removed the port forwarding and add the suggested IP monitor of 8.8.8.8 and 8.8.4.4</p>
<p dir="auto">I did the the hybrid nat. See below.</p>
<p dir="auto">In firewall/nat/outbound, do I still need those four OpenVpn interfaces?</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/pf4.JPG" alt="pf4.JPG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pf4.JPG_thumb" alt="pf4.JPG_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pf5.JPG" alt="pf5.JPG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pf5.JPG_thumb" alt="pf5.JPG_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pf6.JPG" alt="pf6.JPG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pf6.JPG_thumb" alt="pf6.JPG_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/690613</link><guid isPermaLink="true">https://forum.netgate.com/post/690613</guid><dc:creator><![CDATA[patrick0525]]></dc:creator><pubDate>Sat, 01 Apr 2017 22:32:52 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: two clients in a gateway group on Sat, 01 Apr 2017 21:42:51 GMT]]></title><description><![CDATA[<p dir="auto">Set the monitor IPs on your VPN gateways to something public like 8.8.8.8 and 8.8.4.4</p>
<p dir="auto">I didn't read that guide but I don't know what the port forwards are for? I don't use any port forwarding for VPN?</p>
<p dir="auto">Use Hybrid Outbound NAT rules, that way you keep all of the auto rules and your manual rules.</p>
]]></description><link>https://forum.netgate.com/post/690606</link><guid isPermaLink="true">https://forum.netgate.com/post/690606</guid><dc:creator><![CDATA[pfBasic]]></dc:creator><pubDate>Sat, 01 Apr 2017 21:42:51 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: two clients in a gateway group on Sat, 01 Apr 2017 17:38:23 GMT]]></title><description><![CDATA[<p dir="auto">I have been using this link as a guide : https://nguvu.org/pfsense/pfsense-multi-vpn-wan/</p>
<p dir="auto">I was sending everything through WAN_DHCP(default) and then added  VPN1_WAN and VPN2_WAN as new gateways. VPN1_WAN and VPN2_WAN are in gateway group called VPN_Group_packet_loss. In here, I also set WAN_DHCP to never.</p>
<p dir="auto">How do I set the the firewall settings properly?</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/pf_1.JPG" alt="pf_1.JPG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pf_1.JPG_thumb" alt="pf_1.JPG_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pf2.JPG" alt="pf2.JPG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pf2.JPG_thumb" alt="pf2.JPG_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pf3.JPG" alt="pf3.JPG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pf3.JPG_thumb" alt="pf3.JPG_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/690552</link><guid isPermaLink="true">https://forum.netgate.com/post/690552</guid><dc:creator><![CDATA[patrick0525]]></dc:creator><pubDate>Sat, 01 Apr 2017 17:38:23 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: two clients in a gateway group on Sat, 01 Apr 2017 03:56:00 GMT]]></title><description><![CDATA[<p dir="auto">OK, that is how i read it and it is correct.  I have 4 VPNs at Tier1 and the naked WAN at Tier5.  This passes the wife test as failing safe.  Thanks!</p>
]]></description><link>https://forum.netgate.com/post/690501</link><guid isPermaLink="true">https://forum.netgate.com/post/690501</guid><dc:creator><![CDATA[BrianX]]></dc:creator><pubDate>Sat, 01 Apr 2017 03:56:00 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: two clients in a gateway group on Sat, 01 Apr 2017 02:52:24 GMT]]></title><description><![CDATA[<p dir="auto">Tiers in gateway groups require all gateways in a tier to go down before it will use a gateway in the next tier.</p>
<p dir="auto">Ex:<br />
GW1: Tier 1<br />
GW2: Tier 1<br />
GW3: Tier 2<br />
GW4: Tier 3</p>
<p dir="auto">If none are down Tier 1 is used<br />
If one is down Tier 1 is used<br />
If two is down Tier 1 is used<br />
If one and two are down Tier 2 is used<br />
If one and three are down Tier 1 is used<br />
If one two and three are down Tier 3 is used</p>
]]></description><link>https://forum.netgate.com/post/690497</link><guid isPermaLink="true">https://forum.netgate.com/post/690497</guid><dc:creator><![CDATA[pfBasic]]></dc:creator><pubDate>Sat, 01 Apr 2017 02:52:24 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: two clients in a gateway group on Sat, 01 Apr 2017 02:43:51 GMT]]></title><description><![CDATA[<p dir="auto">is it any or all of the VPNs going down?  that part was not entirely clear.</p>
<p dir="auto">but yeah, this is sort of a hedge against ISP targeted marketing and sticking crap into packets/web pages.  i actually only shuffle traffic from certain systems out the VPNs, so things like Xbox and PS work with as little drama as possible.  (DNS, http, https, and a few other non-basic protocols)</p>
]]></description><link>https://forum.netgate.com/post/690494</link><guid isPermaLink="true">https://forum.netgate.com/post/690494</guid><dc:creator><![CDATA[BrianX]]></dc:creator><pubDate>Sat, 01 Apr 2017 02:43:51 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: two clients in a gateway group on Sat, 01 Apr 2017 02:26:49 GMT]]></title><description><![CDATA[<p dir="auto">I'm glad it worked out for you!</p>
<p dir="auto">Keep in mind that if you are using VPNs for anonymity then in this setup you will broadcast your real IP if your VPNs go down, which is not desirable. If you don't care about anonymity then that's fine.</p>
<p dir="auto">FWIW the only time all of my VPN clients (or even two of them) have gone down was when my WAN port got a lot of packet loss for a few hours.</p>
]]></description><link>https://forum.netgate.com/post/690492</link><guid isPermaLink="true">https://forum.netgate.com/post/690492</guid><dc:creator><![CDATA[pfBasic]]></dc:creator><pubDate>Sat, 01 Apr 2017 02:26:49 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: two clients in a gateway group on Sat, 01 Apr 2017 01:51:21 GMT]]></title><description><![CDATA[<p dir="auto">i just did this very thing.  (except i used 4 VPNs and the WAN in a group, with the VPNs as tier1 and the WAN as tier5).</p>
<p dir="auto">i think that should allow me to RR all my traffic between four different VPN vendors, plus fall back to WAN in the case of them all being offline.</p>
]]></description><link>https://forum.netgate.com/post/690489</link><guid isPermaLink="true">https://forum.netgate.com/post/690489</guid><dc:creator><![CDATA[BrianX]]></dc:creator><pubDate>Sat, 01 Apr 2017 01:51:21 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: two clients in a gateway group on Fri, 31 Mar 2017 23:57:18 GMT]]></title><description><![CDATA[<p dir="auto">Interfaces / Interface Assignments: Next to "Available network ports:" select your VPN client from the dropdown, click "+ ADD" Repeat for all clients</p>
<p dir="auto">Click your new VPN interfaces, click "Enable Interface", Save &amp; Apply, Repeat for all clients</p>
<p dir="auto">Then try to setup a gateway group again, you should see your new interfaces.</p>
]]></description><link>https://forum.netgate.com/post/690481</link><guid isPermaLink="true">https://forum.netgate.com/post/690481</guid><dc:creator><![CDATA[pfBasic]]></dc:creator><pubDate>Fri, 31 Mar 2017 23:57:18 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: two clients in a gateway group on Fri, 31 Mar 2017 22:35:21 GMT]]></title><description><![CDATA[<p dir="auto">Assign your clients interfaces and enable them.  I am not sure I did this.<br />
Two VPN clients are enabled/connected to two different VPN servers.</p>
<p dir="auto">How do I configure the next step? No new interfaces show up.</p>
<p dir="auto">Go to System / Routing / Gateway Groups.<br />
Add a new Gateway Group and select all of the clients you want to use as<br />
gateways as Tier 1, make sure any gateways you do not want to use are set to Never.</p>
]]></description><link>https://forum.netgate.com/post/690468</link><guid isPermaLink="true">https://forum.netgate.com/post/690468</guid><dc:creator><![CDATA[patrick0525]]></dc:creator><pubDate>Fri, 31 Mar 2017 22:35:21 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: two clients in a gateway group on Fri, 31 Mar 2017 17:22:34 GMT]]></title><description><![CDATA[<p dir="auto">Yeah, you can have one physical wAN port connected from pfSense to modem, and have 1, 2, 5, etc VPN clients configured into a gateway group acting over that one WAN port.</p>
<p dir="auto">The usual reason to use multiple VPN clients in a gateway group is to utilize multiple cores. So it's probably not worthwhile to have more clients than you have CPU cores.</p>
]]></description><link>https://forum.netgate.com/post/690396</link><guid isPermaLink="true">https://forum.netgate.com/post/690396</guid><dc:creator><![CDATA[pfBasic]]></dc:creator><pubDate>Fri, 31 Mar 2017 17:22:34 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: two clients in a gateway group on Fri, 31 Mar 2017 17:03:44 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for clearing it up. I was mistaken for talking about  lan. It should have been wan instead.</p>
<p dir="auto">I guess you could have number of VPN clients connected  to different VPN server, and then  gateway grouped to maximize performance.</p>
<p dir="auto">Thanks</p>
]]></description><link>https://forum.netgate.com/post/690389</link><guid isPermaLink="true">https://forum.netgate.com/post/690389</guid><dc:creator><![CDATA[patrick0525]]></dc:creator><pubDate>Fri, 31 Mar 2017 17:03:44 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: two clients in a gateway group on Fri, 31 Mar 2017 16:44:34 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/patrick0525">@<bdi>patrick0525</bdi></a>:</p>
<blockquote>
<p dir="auto">I am planning to use one LAN port for both vpn clients.</p>
</blockquote>
<p dir="auto">I'm not sure what you mean by this? VPN Gateways will work over your WAN port as they are gateways to the internet. You don't need 1:1 physical port to VPN Client if that's what you mean?</p>
]]></description><link>https://forum.netgate.com/post/690375</link><guid isPermaLink="true">https://forum.netgate.com/post/690375</guid><dc:creator><![CDATA[pfBasic]]></dc:creator><pubDate>Fri, 31 Mar 2017 16:44:34 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: two clients in a gateway group on Fri, 31 Mar 2017 08:36:11 GMT]]></title><description><![CDATA[<p dir="auto">Thanks. I will setup another vpn client to a different vpn provider server. I am planning to use one LAN port for both vpn clients. That is ok ? Right?</p>
]]></description><link>https://forum.netgate.com/post/690300</link><guid isPermaLink="true">https://forum.netgate.com/post/690300</guid><dc:creator><![CDATA[patrick0525]]></dc:creator><pubDate>Fri, 31 Mar 2017 08:36:11 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: two clients in a gateway group on Fri, 31 Mar 2017 05:32:04 GMT]]></title><description><![CDATA[<ul>
<li>
<p dir="auto">Create another client identical to the one you've already created. (If you have the option to choose from multiple servers I would recommend that you test them all and select the two fastest servers for your two clients, this way if one server is performing poorly, you can mitigate it by grouping it with a different server).</p>
</li>
<li>
<p dir="auto">Assign your clients interfaces and enable them.</p>
</li>
<li>
<p dir="auto">Go to System / Routing / Gateway Groups.<br />
Add a new Gateway Group and select all of the clients you want to use as gateways as Tier 1, make sure any gateways you do not want to use are set to Never.</p>
</li>
<li>
<p dir="auto">Edit all relevant firewall rules to use only the gateway group you created. (Advanced Options &gt; Gateway)</p>
</li>
</ul>
]]></description><link>https://forum.netgate.com/post/690272</link><guid isPermaLink="true">https://forum.netgate.com/post/690272</guid><dc:creator><![CDATA[pfBasic]]></dc:creator><pubDate>Fri, 31 Mar 2017 05:32:04 GMT</pubDate></item></channel></rss>