Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN DNS and LAN Not Working

    Scheduled Pinned Locked Moved OpenVPN
    openvpn problempfsense
    8 Posts 2 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      fabiolanza
      last edited by

      Hi, I configured OpenVPN server for access to local LAN and also DNS. However, these configs are not working. After connected, DNS and LAN not working.

      I have the screenshots of my configs, are you able to provide any advice? I am using Viscosity for Windows as OpenVPN client. I also tried to add local DNS and local route in Viscosity client but it did not work the same so I left it not filled, as this info should be being pushed by the server either way.

      OpenVPN subnet: 10.0.5.0/24 (GW 10.0.5.1)
      LAN subnet: 10.0.1.0/24 (GW 10.0.1.1)

      I have the same problem when connecting to the VPN from my mobile phone.

      Thanks

      alt text
      alt text
      alt text
      alt text
      alt text

      1 Reply Last reply Reply Quote 0
      • DaddyGoD
        DaddyGo
        last edited by

        Please configure the OpenVPN based on this (via wizard):
        https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/openvpn-remote-access-server.html

        then use the OpenVPN Client Export Package:
        https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/using-the-openvpn-client-export-package.html

        if it still does not work we can start solving the problem.

        Cats bury it so they can't see it!
        (You know what I mean if you have a cat)

        1 Reply Last reply Reply Quote 0
        • F
          fabiolanza
          last edited by

          Hi, I did use these tutorials to generate the configuration files. Unfortunately I am going through these issues. If there is any advice that could be shared I would appreciate. Thanks!

          1 Reply Last reply Reply Quote 0
          • DaddyGoD
            DaddyGo
            last edited by

            Which version of pfSense are you using?
            Please pay attention to this:

            ee9c3ee6-64d2-4843-b3c0-b3db37269ec8-image.png

            Cats bury it so they can't see it!
            (You know what I mean if you have a cat)

            F 1 Reply Last reply Reply Quote 0
            • F
              fabiolanza @DaddyGo
              last edited by

              @DaddyGo you mean the Force all client-generated IPv4 traffic through the tunnel? If I am not mistaken I did try with that earlier but I will try later today again. What about the DNS issue, any thoughts?

              Thanks again, very respectively,

              Fabio

              1 Reply Last reply Reply Quote 0
              • DaddyGoD
                DaddyGo
                last edited by

                In pfsense, this OpenVPN function works very well, with Wizard + Client Export, so this is always the starting point, if it is OK then you can experiment with individual clients and more... (like Viscosity client), always go through the wizard and you can refine your settings later.

                For help, I upload "PNGs" of this one of our pfSense box settings.OpenVPN_server.zip

                In my case DNS always points to the box (since I use Unbound) and for windows10 don't forget that either:

                11540e45-af03-46d8-a887-5624ebf5f4b9-image.png

                In case the VPN connection is established with basic settings (above), then the logs tell you a lot about the possible problems, if you experiment with your custom setting.

                Cats bury it so they can't see it!
                (You know what I mean if you have a cat)

                1 Reply Last reply Reply Quote 1
                • F
                  fabiolanza
                  last edited by

                  Hi @DaddyGo, I looked into the file you share and I could not understand where my problem is. I attached a print-out of my server settings in PDF. Please see attached: pfSense.lanza.local - VPN_ OpenVPN_ Servers_ Edit.zip

                  The issue is that no route is being set for my local network. Ping does not work, tracert does not work too. I can't ping the local LAN gateway (10.0.1.1). I also checked with firewall and all configs are there. Not really sure what to change next.

                  Any advice based on the PDF I shared?

                  Thanks

                  1 Reply Last reply Reply Quote 0
                  • DaddyGoD
                    DaddyGo
                    last edited by

                    Hi,
                    Because of the differences, is it still a question for me which pfSense version is this?
                    (for example, it's a difference...)

                    a5e04914-dd2a-4541-837e-1c1e7326f70d-image.png

                    The second important thing is server mode (you use TLS), but that's all I see:

                    a4666822-e747-4e05-9657-82e796510e7c-image.png

                    instead of:

                    0b4e10a0-be71-4b2c-ad2c-d118a3478c69-image.png

                    I don't see your own cert for the connection either:

                    8b5bbbd9-235b-4183-94a3-d0bd6e1d3d4e-image.png

                    instead of:

                    8fd16d58-39b6-45f3-a24c-c4f941401cf3-image.png

                    like:
                    ff6291f2-6a01-4d33-866c-1f5c2019df89-image.png

                    and even a VPN User is required:

                    3397cc2b-5bbd-4e55-933a-bccc0f134c07-image.png

                    with:

                    a4585c69-0d7d-49a8-8bc9-792285643332-image.png

                    exactly where does the DNS (10.0.1.31) point?? this is the box itself or a separate DNS server on the network

                    Cats bury it so they can't see it!
                    (You know what I mean if you have a cat)

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.