Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    OpenVPN gateway behaviors

    OpenVPN
    2
    4
    81
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      meaglerick last edited by

      I'm hoping someone can shed some light on this behavior, since I can't seem to find anything in the documentation on it. I know that TLS/SSL OpenVPN (site-to-site) behaves differently than shared key, but why do the gateways behave differently?

      I have created two OpenVPN servers on one pfsense box, and two OpenVPN clients on another pfsense box. They are configured with the same encryption, route, and gateway parameters, except one is SSL/TLS OpenVPN and the other is shared key. I have created the VPN interfaces on both servers and both clients, and enabled the firewall rules on both servers and both clients.

      Why does the shared key gateway get a "dynamic" gateway and the certificate based VPN gets assigned an address and the gateway comes online?

      99120cac-82fd-4506-8d8c-eec699395aee-image.png

      Certificate based OpenVPN is Online, whereas the shared key version is Pending

      This has been happening whether I configure the OpenVPN server tunnel network as a /30 network or anything larger than that.

      I would like to be able to use the shared key VPN for it's simplicity with two firewalls, but the lack of gateway monitoring is just not good for routing and rules.

      Thank you.

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @meaglerick last edited by

        @meaglerick
        I suspect you're missing the Tunnel Network setting on the client. Use a /30 mask and enter the network on both sites.

        M 1 Reply Last reply Reply Quote 0
        • M
          meaglerick @viragomann last edited by

          @viragomann Ok, I tried adding the tunnel network on the client VPN device, using both a /29, and a /30, and now the gateway shows up and configures itself. Question now is...why do I not have to configure the tunnel network on the SSL/TLS based VPN client, but on the shared key version, I do? I was under the impression they operated very similarly.

          Thank you.

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @meaglerick last edited by

            @meaglerick
            I think, that is the wrong place to ask this. Possibly you have luck in the OpenVPN community forum.

            We are just following here the guides provided by Netgate:
            https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-s2s-psk.html
            https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-s2s-tls.html

            1 Reply Last reply Reply Quote 0
            • First post
              Last post

            Products

            • Platform Overview
            • TNSR
            • pfSense
            • Appliances

            Services

            • Training
            • Professional Services

            Support

            • Subscription Plans
            • Contact Support
            • Product Lifecycle
            • Documentation

            News

            • Media Coverage
            • Press
            • Events

            Resources

            • Blog
            • FAQ
            • Find a Partner
            • Resource Library
            • Security Information

            Company

            • About Us
            • Careers
            • Partners
            • Contact Us
            • Legal
            Our Mission

            We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

            Subscribe to our Newsletter

            Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

            © 2021 Rubicon Communications, LLC | Privacy Policy