<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Help with OpenVPN config for a site to site vpn config..]]></title><description><![CDATA[<p dir="auto">I have two Intel servers setup running PFsense 2.4.1.  I have a pile of IPsec VPN's working like a charm on the one server, but I need to create a VPN from a site with a dynamic IP back to the main location, and from what I have read that is not an IPsec option, so looks like OpenVPN client/server will do the job.</p>
<p dir="auto">That said, I have tried using the docs in the wiki for a shared key setup, and I am trying to do the following:</p>
<p dir="auto">LAN-A (10.3.0.0/16) -PFS_A–  Internet  --PFS_B- LAN-B (10.4.0.0/16)</p>
<p dir="auto">PFS_A Config:</p>
<p dir="auto">Server Mode:  Peer to Peer (Shared Key)<br />
Protocol:  UDP on IPv4 Only<br />
Device Mode:  tun<br />
Interface:  WAN<br />
Local Port:  1194</p>
<p dir="auto">Shared Key generated!</p>
<p dir="auto">Encryption:  AES-256-CBC<br />
Auth Digest:  SHA512</p>
<p dir="auto">IPv4 Tunnel Net:  172.30.1.0/30<br />
IPv4 Remote Net:  10.4.0.0/16<br />
Compression:  Adaptive LZO</p>
<p dir="auto">On the Client server I have the following.</p>
<p dir="auto">Client PFS_B:</p>
<p dir="auto">Server Mode:  Peer to Peer (Shared Key)<br />
Protocol:  UDP on IPv4 Only<br />
Device Mode:  tun<br />
Interface:  WAN<br />
Server Address:  50.225.xx.yy<br />
Local Port:  1194</p>
<p dir="auto">Shared Key copied from Server!</p>
<p dir="auto">Encryption:  AES-256-CBC<br />
Auth Digest:  SHA512</p>
<p dir="auto">IPv4 Tunnel Net:  172.30.1.0/30<br />
IPv4 Remote Net:  10.3.0.0/16<br />
Compression:  Adaptive LZO</p>
<p dir="auto">So one side is pretty much a perfect match with the other, outside of one being server side, and one being client side.  I have even setup on each side systems to keep a ping going each direction.  Still server side all I see is:</p>
<p dir="auto">Peer to Peer Server Instance Statistics<br />
Name Status Connected Since Virtual Address Remote Host Bytes Sent / Received Service<br />
Server UDP4:1194 0 B / 0 B</p>
<p dir="auto">Client side I see:</p>
<p dir="auto">OpenVPN Clients<br />
Protocol Server Description Actions<br />
UDP4 50.225.xx.yy:1194 VPN Link</p>
<p dir="auto">I have also made sure I had firewall rules in allowing the connection to the server on 1194, and I have also added a VPN rule that just permits all traffic inside the VPN.</p>
<p dir="auto">I am sure I am probably missing something silly, but hopefully someone here can point me in the right direction to get this all working.</p>
<p dir="auto">Thanks...</p>
]]></description><link>https://forum.netgate.com/topic/123145/help-with-openvpn-config-for-a-site-to-site-vpn-config</link><generator>RSS for Node</generator><lastBuildDate>Thu, 18 Jun 2026 08:11:39 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/123145.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 17 Nov 2017 06:22:56 GMT</pubDate><ttl>60</ttl></channel></rss>