Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Extra OpenVPN interface?

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • valnarV
      valnar
      last edited by

      Sorry for what will probably be a n00b question..

      I have an APU2C4 board (standard 3 ethernet interfaces, only using 2).  I followed some directions to create an OpenVPN server on pfSense so I can VPN into my home remotely.  It works well, but I notice I have two FW interfaces for it. One is called OVPN (which is what I renamed it) and the other is simply OpenVPN which I believe was created when I did the wizard.  Why both?  Can I get rid of one of them?  And if so, how?  Which is used?

      Interfaces.jpg
      Interfaces.jpg_thumb
      FW-rules.jpg
      FW-rules.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        The OpenVPN is an interface group which is automatically created when you activate an OpenVPN instance, server or client.
        You have assigned an interface to the server instance, this is now a member of the OpenVPN interface group.

        However, you can ignore OpenVPN and define all your firewall rules on the OVPN interface. But consider that also rules on OpenVPN would take effect.

        1 Reply Last reply Reply Quote 0
        • valnarV
          valnar
          last edited by

          OK so it's a phantom loopback or something similar?  I don't see it listed under interface groups.  We just ignore it then? Does everyone get it, or was it the way I configured it?

          yes, I'll put my rules under OVPN.  Thanks!

          1 Reply Last reply Reply Quote 0
          • V
            viragomann
            last edited by

            The OpenVPN interface group is inevitably created by pfSense. Since you need to route traffic over your VPN, you had to assign an interface to you OpenVPN server instance additionally.
            The interface group is created one-off when OpenVPN is set up and all OpenVPN instances are unavoidably added to it.

            1 Reply Last reply Reply Quote 0
            • valnarV
              valnar
              last edited by

              OK thank you.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.