Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Vpn gets Up on server, but Donw on Client

    Scheduled Pinned Locked Moved OpenVPN
    10 Posts 3 Posters 839 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jucelio_rosa
      last edited by

      Good Morning.
      Scenario:
      Headquarters of the company where I have pfsense 2.2.6. I configured, in Vpn \ OpenVpn \ Server, the vpn server.
      I configured a Peer to Peer (Shared Key) vpn, on port 1196 (1194 is busy),protocol: UDP, Encryption algorithm: aes-256-cbc (256 bit), tunnel network: 10.12.0.0/24, remote network: 192.168.0.0/ 24 (lan from where the client is).

      An Alias ​​has been created pointing to the client WAN ip.
       Rule was created, allowing data traffic coming from Alias ​​on port 1196.

      Client
      Pfsense Version 2.4.4.

      I configured, in Vpn \ OpenVpn \ Client, the Client. I don't have all the data here right now, but I think I did everything the right way. Peer to Peer (Shared Key), protocol: UDP, interface: WAN, Server Port: 1196, Encryption algorithm: aes-256-cbc (256 bit), tunnel network: 10.12.0.0/24, IPv4 Remote Network / s: I put the server WAN ip.

      Shared Key: Key generated on the server.

      Error :
      On the server, vpn status is UP, but on Client VPN status is Donw.
      I don't understand what may be happening.

      1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by

        2.2.6 is very old and unsupported.
        Upgrade to the latest version first.

        -Rico

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by johnpoz

          2015-12-21

          That is when 2.2.6 came out - JFC people... How can anyone think that is ok to not update their firewall? I can see being a bit behind, corp change control etc. etc. But 4 years??

          Prob good opportunity to also change out the hardware, since have to assume its 4+ years old as well?

          What version of openvpn could that be? 2.3.7, maybe .8?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • J
            jucelio_rosa
            last edited by

            Ok. I'll update. I took over the IT department recently and didn't upgrade.

            1 Reply Last reply Reply Quote 0
            • J
              jucelio_rosa
              last edited by

              Good afternoon.
              Checking the log, I noticed that there was the error "Bad Compression Stub Unpacking Header Byte (69)".

              In the vpn settings, in the Comopression field, I selected the "Omit Preference (use Open Vpn Default)" option.

              The error is no longer happening, it is already possible to access some servers at corporate headquarters, but I cannot communicate with the AD server. I also can't communicate with clients (users' computers) at headquarters.

              1 Reply Last reply Reply Quote 0
              • J
                jucelio_rosa
                last edited by

                Alias:

                Alias_rede_cliente.png

                1 Reply Last reply Reply Quote 0
                • J
                  jucelio_rosa
                  last edited by

                  Rule:

                  regra criada para permitir o acesso a lan da embaixada.png

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    Doesn't look updated to me...

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • J
                      jucelio_rosa
                      last edited by

                      Not really updated yet.
                      At the moment I can not upgrade, as it would impact the work of users. I can do it only on the weekend.

                      1 Reply Last reply Reply Quote 0
                      • RicoR
                        Rico LAYER 8 Rebel Alliance
                        last edited by

                        I'd suggest you to grab a spare box and perform the update there / restore your config to make sure everything is going smooth.
                        Risky to upgrade from a very old version with just one box if you run critical stuff there.

                        -Rico

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.