• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[SOLVED] Local DNS over OpenVPN

Scheduled Pinned Locked Moved OpenVPN
7 Posts 3 Posters 641 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    manjotsc
    last edited by manjotsc Feb 11, 2021, 10:35 PM Feb 11, 2021, 2:46 AM

    I am trying to get local dns resolve working on openvpn, but no luck. My Pfsense ip is 192.168.40.1

    OpenVPN Config

    Screenshot_2021-02-10 firewall manjot net - VPN OpenVPN Servers Edit(1).png

    Screenshot_2021-02-10 firewall manjot net - VPN OpenVPN Servers Edit(2).png

    Screenshot_2021-02-10 firewall manjot net - VPN OpenVPN Servers Edit(3).png

    Screenshot_2021-02-10 firewall manjot net - VPN OpenVPN Servers Edit(4).png

    Screenshot_2021-02-10 firewall manjot net - VPN OpenVPN Servers Edit(5).png

    Screenshot_2021-02-10 firewall manjot net - VPN OpenVPN Servers Edit(6).png

    Vendor: HP
    Version: P01 Ver. 02.50
    Release Date: Wed Jul 17 2024
    Boot Method: UEFI
    24.11-RELEASE (amd64)
    FreeBSD 15.0-CURRENT
    CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
    Current: 3606 MHz, Max: 3400 MHz
    4 CPUs : 1 package(s) x 4 core(s)

    V 1 Reply Last reply Feb 11, 2021, 2:11 PM Reply Quote 0
    • V
      viragomann @manjotsc
      last edited by Feb 11, 2021, 2:11 PM

      @manjotsc
      Is DNS access to 192.168.40.1 allowed on the OpenVPN interface?

      Did you include the domain in the hostname when you try to access it?

      J 1 Reply Last reply Feb 11, 2021, 2:28 PM Reply Quote 0
      • J
        johnpoz LAYER 8 Global Moderator @viragomann
        last edited by Feb 11, 2021, 2:28 PM

        Common mistake when trying to do this is the unbound ACLs

        By default unbound ACLs allow for any locally attached network to query it. But this does not include your vpn tunnel network.. So if you want vpn clients to be able to query your unbound running on pfsense you would have to create/adjust your unbound ACLs to allow the vpn tunnel network.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        M 1 Reply Last reply Feb 11, 2021, 6:53 PM Reply Quote 0
        • M
          manjotsc @johnpoz
          last edited by Feb 11, 2021, 6:53 PM

          @johnpoz @viragomann This is what I have as settings

          Screenshot 2021-02-11 135157.png

          Screenshot 2021-02-11 135249.png

          Vendor: HP
          Version: P01 Ver. 02.50
          Release Date: Wed Jul 17 2024
          Boot Method: UEFI
          24.11-RELEASE (amd64)
          FreeBSD 15.0-CURRENT
          CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
          Current: 3606 MHz, Max: 3400 MHz
          4 CPUs : 1 package(s) x 4 core(s)

          J 1 Reply Last reply Feb 11, 2021, 7:01 PM Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator @manjotsc
            last edited by Feb 11, 2021, 7:01 PM

            Well do a query direct from the client.. Do you timeout, do you get back a refused..

            Sniff on pfsense vpn interface, do you see the query come down the vpn..

            I always turn off the automatic acls - not sure if when that is active, if manual acls are used..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            M 2 Replies Last reply Feb 11, 2021, 10:03 PM Reply Quote 0
            • M
              manjotsc @johnpoz
              last edited by Feb 11, 2021, 10:03 PM

              @johnpoz OpenVPN logs are flooded with these

              Feb 11 14:08:23	openvpn	16284	admin/204.48.94.175:33001 UDPv4 READ [124] from [AF_INET]204.48.94.175:33001: P_DATA_V2 kid=0 DATA len=123
              Feb 11 14:08:22	openvpn	16284	admin/204.48.94.175:33001 Authenticate/Decrypt packet error: cipher final failed
              

              Vendor: HP
              Version: P01 Ver. 02.50
              Release Date: Wed Jul 17 2024
              Boot Method: UEFI
              24.11-RELEASE (amd64)
              FreeBSD 15.0-CURRENT
              CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
              Current: 3606 MHz, Max: 3400 MHz
              4 CPUs : 1 package(s) x 4 core(s)

              1 Reply Last reply Reply Quote 0
              • M
                manjotsc @johnpoz
                last edited by Feb 11, 2021, 10:34 PM

                @johnpoz Update : The Issue is fixed now by re exporting the client profile and dns is also seems to be working.

                Vendor: HP
                Version: P01 Ver. 02.50
                Release Date: Wed Jul 17 2024
                Boot Method: UEFI
                24.11-RELEASE (amd64)
                FreeBSD 15.0-CURRENT
                CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
                Current: 3606 MHz, Max: 3400 MHz
                4 CPUs : 1 package(s) x 4 core(s)

                1 Reply Last reply Reply Quote 0
                1 out of 7
                • First post
                  1/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received