OpenVPN server static IP
-
Maybe you need to play around a bit with those parameters.
Check https://forum.netgate.com/topic/115495/openvpn-fast-io-and-sndbuf-rcvbuf-options-in-the-gui and https://redmine.pfsense.org/issues/7507-Rico
-
@rico said in OpenVPN server static IP:
You should stay in standard tun mode, only switch to tap if you really need to.
-Rico
He said "I see that but my goal is to be on the same subnet as the lan side. Is there a way?". The only way that's going to happen is with TAP. Tun requires a separate subnet.
Here's some info on what he wants to do:
-
I know what he asked and what a bridge is.
99% of people asking for this do not really need to carry layer 2 over VPN and just want to have the same subnet for some kind of cosmetic reason.
For most scenarios to cover layer 3 is just fine, in OpenVPN it is widely supported, more stable, less overhead.
If you really need to transfer layer 2 stuff...sure go for tap mode, but you need to live with the donwsides then.-Rico
-
Wanted to give an update. TAP VPN has been working great! Everything works and the speed issue was my connection where I was. Thank you for everyones help!! PFsense is awesome!!
-
By the way... What is the con of doing TAP vs TUN VPN?
-
TAP benefits:
- behaves like a real network adapter (except it is a virtual network adapter)
- can transport any network protocols (IPv4, IPv6, Netalk, IPX, etc, etc)
- Works in layer 2, meaning Ethernet frames are passed over the VPN tunnel
- Can be used in bridges
TAP drawbacks
- causes much more broadcast overhead on the VPN tunnel
- adds the overhead of Ethernet headers on all packets transported over the VPN tunnel
- scales poorly
- can not be used with Android or iOS devices
TUN benefits:
- A lower traffic overhead, transports only traffic which is destined for the VPN client
- Transports only layer 3 IP packets
TUN drawbacks:
- Broadcast traffic is not normally transported
- Can only transport IPv4 (OpenVPN 2.3 adds IPv6)
- Cannot be used in bridges
-Rico
-
Awesome write up! Do you know or heard when the IOS app will be possibly updated to work on TAP? I have some programs I have written but being on TUN VPN break certain features.
-
"The iOS VPN API supports only tun-style tunnels at the moment. This is a limitation of the iOS platform. If you try to connect a profile that uses a tap-based tunnel, you will get an error that only layer 3 tunnels are currently supported."
(https://openvpn.net/faq/why-doesnt-the-app-support-tap-style-tunnels/)-Rico
-
Oh I am aware. What I am asking is if you heard about any development on adding TAP to IOS?
-
As long as Apple does not open their API for TAP there will never be any support for it.
ATM it would only be possible in jailbreak mode.-Rico
-
I appreciate your input but not sure if thats the real reason. I know it can be done on the IOS platform becuase at work we have cisco anyconnect and sonic wall VPNs that do it just fine. So maybe in the future it will be added. Other wise, I am happy with PFsense and the community!