• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

OpenVPN server via stunnel @pfsense - routing not working

Scheduled Pinned Locked Moved OpenVPN
2 Posts 2 Posters 717 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    jacotec
    last edited by jacotec Mar 28, 2019, 12:30 PM Mar 28, 2019, 12:27 PM

    Hi,

    perparing a business trip to China (where I need to have a working VPN to my home) I've read that the most secure way that the VPN works is to tunnel the OVPN through stunnel as even OVPN over port 443/TCP with TLS-crypt is described to be blocked by the GFW.

    I've set this up with the stunnel package in pfsense, I can establish the OVPN connection but finally I can't ping my internal hosts nor connect to the internet through the tunnel. Something is missing.

    I've set up an OVPN server, listening on port 443 TCP on an internal interface (10.0.0.5).

    Using a NAT rule to route port 8443 from the WAN to 10.0.0.5:443 via NAT works just fine. I can connect with the client and reach all internal hosts and the internet via my pfsense.

    I've configured stunnel to listen on the internal interface 10.0.0.2 port 8443. Forwarding to 10.0.05 port 443 (my VPN server).

    I now change the NAT to route WAN port 8443 to 10.0.0.2:8443 (the stunnel server). When I connect the OVPN client via stunnel now, I can establish the OVPN connection from the client just fine. But I can't ping any internal host nor reach the internet.

    So, the working config:

    --> WAN port 8443 --> [pfS NAT] --> 10.0.0.5:443 [OVPN server)

    And that's what not works:

    --> WAN port 8443 --> [pfS NAT] --> 10.0.0.2:8443 [stunnel] --> 10.0.0.5:443 [OVPN server]

    What did I miss?

    J 1 Reply Last reply Mar 28, 2019, 9:27 PM Reply Quote 0
    • J
      JKnott @jacotec
      last edited by Mar 28, 2019, 9:27 PM

      @jacotec said in OpenVPN server via stunnel @pfsense - routing not working:

      What did I miss?

      You might have some "fun" getting through the Great Firewall of China. Using an unauthorized VPN is illegal there. A fried of mine worked in China for a while and couldn't get a firewall to work.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      1 Reply Last reply Reply Quote 0
      2 out of 2
      • First post
        2/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received