Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Ensuring against IP leaks - a challenge?

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 5 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tonynibbles
      last edited by

      Hi everyone,

      (first post, n00b, yes hi)

      I bought a Netgate SG-3100 at the start of the year and, apart from the occasional ups and downs, I've have been pretty pleased with it and pfSense.
      I run a few OpenVPN connections (grouped, for failover - great pfSense feature) and the majority of my network traffic runs through them. Overall, along with DNS leak prevention, privacy-wise, things seem pretty good - much thanks to the excellent guide on techhelpguides.

      I can check my exposed IP on sites like google.com, www.whatismyip.com, dnsleaktest.com, astrill.com/vpn-leak-test - any number of sites and they all report the IP of my active VPN connection.

      BUT - there is one site which reports my actual IP. The beautifully simple http://whatismyip.host - and it's driven me a bit mad!
      I even contacted them to ask how they're achieving such an excellent result and they suggested it might be my VPN provider setting the X-Forwarded-For header - but alas, I've checked and this isn't the case.

      So, my question is really - Does anyone else get unexpected results using http://whatismyip.host?

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        So, my question is really - Does anyone else get unexpected results using http://whatismyip.host?

        No.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • M
          MoonKnight
          last edited by

          @tonynibbles:

          So, my question is really - Does anyone else get unexpected results using http://whatismyip.host?

          No :)

          --- 24.11 ---
          Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
          Kingston DDR4 2666MHz 16GB ECC
          2 x HyperX Fury SSD 120GB (ZFS-mirror)
          2 x Intel i210 (ports)
          4 x Intel i350 (ports)

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            This post actually looks like spam.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • T
              tonynibbles
              last edited by

              Well, it might be a bit wordy but I can assure you it's not spam - a genuine query as to whether this is just me or not.

              Thanks for the replies, I'm still at a loss as to where my fault is and why this site and only this site reports my IP, but I will persevere.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                So I just turned my policy route rule to send client out vpn.  I then made sure client was using quad9 for dns vs pfsense as resolver and hit up whats my IP and your website both showing my vpn IP.. So not sure what your doing exactly.  But without details it will be impossible for anyone to help you spot what your doing wrong, etc.

                Turned policy rule off and back to my normal wan IP from isp.

                policyroutepng.png
                policyroutepng.png_thumb
                Selection_027.png
                Selection_027.png_thumb

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  @tonynibbles:

                  Well, it might be a bit wordy but I can assure you it's not spam - a genuine query as to whether this is just me or not.

                  Thanks for the replies, I'm still at a loss as to where my fault is and why this site and only this site reports my IP, but I will persevere.

                  It is showing your IP address because you have your system configured to send it out the WAN not the OpenVPN.

                  No way to know what in your configuration is wrong unless you show us what you have done.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • T
                    tonynibbles
                    last edited by

                    Well, fwiw my system setup uses much of the advice in the techhelpguides article, VPNs are configured as a Gateway group consisting of four VPN connections, the load balancing handles when one becomes too slow.

                    A firewall rule on the LAN tells all outbound traffic to use the VPN Gateway Group.

                    I'm a little less familiar with the DNS setup, but I've used the DNS Resolver method ("Leak Prevention Method 2") from the tech help guides.

                    My setup appears to work well, apart from this one site which reports my IP. Everything else, Google, dnsleak, ipleak, whatismyip - they all report my VPN IP. This is why it's so frustrating - something's getting through but I can't be sure how.

                    There are so many settings in PFsense it seems impossible to convey every detail of my config - I suppose a better question would be, what tools do people use to debug this?

                    ![Screen Shot 2018-04-16 at 23.01.14.png](/public/imported_attachments/1/Screen Shot 2018-04-16 at 23.01.14.png)
                    ![Screen Shot 2018-04-16 at 23.01.14.png_thumb](/public/imported_attachments/1/Screen Shot 2018-04-16 at 23.01.14.png_thumb)

                    1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate
                      last edited by

                      Packet captures and wireshark.

                      Diagnostics > States

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • T
                        tonynibbles
                        last edited by

                        Hmmm, ok.

                        Now in states, I can see that if I use Google.com, the request uses one of my VPN connections, but on the other website, the request goes out on WAN. Damn.

                        1 Reply Last reply Reply Quote 0
                        • T
                          tonynibbles
                          last edited by

                          FFFFFFFF

                          OK. I've got it!

                          I am running pfBlocker and have it set to create an alias group of Amazon servers. Requests to these destination IPs are set to bypass the VPN (mostly for content streaming), but in this case because that website was hosted on AWS, it was being delivered on the WAN not the VPN. Hence, it could see my IP.

                          This is the dumbest thing. Thanks for the heads up on figuring this out, was doing my nut in.
                          What a doofus.

                          1 Reply Last reply Reply Quote 0
                          • P
                            pdfteam
                            last edited by

                            No. I am getting same IP results with whatismyip.host and other  websites such as whatismyip.live

                            I am using PureVPN and visited both websites. Here are the results:

                            http://whatismyip.live  IP results:

                            http://whatismyip.host results:

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.