Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [SOLVED] Local DNS over OpenVPN

    OpenVPN
    3
    7
    637
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • manjotscM
      manjotsc
      last edited by manjotsc

      I am trying to get local dns resolve working on openvpn, but no luck. My Pfsense ip is 192.168.40.1

      OpenVPN Config

      Screenshot_2021-02-10 firewall manjot net - VPN OpenVPN Servers Edit(1).png

      Screenshot_2021-02-10 firewall manjot net - VPN OpenVPN Servers Edit(2).png

      Screenshot_2021-02-10 firewall manjot net - VPN OpenVPN Servers Edit(3).png

      Screenshot_2021-02-10 firewall manjot net - VPN OpenVPN Servers Edit(4).png

      Screenshot_2021-02-10 firewall manjot net - VPN OpenVPN Servers Edit(5).png

      Screenshot_2021-02-10 firewall manjot net - VPN OpenVPN Servers Edit(6).png

      Vendor: HP
      Version: P01 Ver. 02.50
      Release Date: Wed Jul 17 2024
      Boot Method: UEFI
      24.11-RELEASE (amd64)
      FreeBSD 15.0-CURRENT
      CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
      Current: 3606 MHz, Max: 3400 MHz
      4 CPUs : 1 package(s) x 4 core(s)

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @manjotsc
        last edited by

        @manjotsc
        Is DNS access to 192.168.40.1 allowed on the OpenVPN interface?

        Did you include the domain in the hostname when you try to access it?

        johnpozJ 1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @viragomann
          last edited by

          Common mistake when trying to do this is the unbound ACLs

          By default unbound ACLs allow for any locally attached network to query it. But this does not include your vpn tunnel network.. So if you want vpn clients to be able to query your unbound running on pfsense you would have to create/adjust your unbound ACLs to allow the vpn tunnel network.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          manjotscM 1 Reply Last reply Reply Quote 0
          • manjotscM
            manjotsc @johnpoz
            last edited by

            @johnpoz @viragomann This is what I have as settings

            Screenshot 2021-02-11 135157.png

            Screenshot 2021-02-11 135249.png

            Vendor: HP
            Version: P01 Ver. 02.50
            Release Date: Wed Jul 17 2024
            Boot Method: UEFI
            24.11-RELEASE (amd64)
            FreeBSD 15.0-CURRENT
            CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
            Current: 3606 MHz, Max: 3400 MHz
            4 CPUs : 1 package(s) x 4 core(s)

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @manjotsc
              last edited by

              Well do a query direct from the client.. Do you timeout, do you get back a refused..

              Sniff on pfsense vpn interface, do you see the query come down the vpn..

              I always turn off the automatic acls - not sure if when that is active, if manual acls are used..

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              manjotscM 2 Replies Last reply Reply Quote 0
              • manjotscM
                manjotsc @johnpoz
                last edited by

                @johnpoz OpenVPN logs are flooded with these

                Feb 11 14:08:23	openvpn	16284	admin/204.48.94.175:33001 UDPv4 READ [124] from [AF_INET]204.48.94.175:33001: P_DATA_V2 kid=0 DATA len=123
                Feb 11 14:08:22	openvpn	16284	admin/204.48.94.175:33001 Authenticate/Decrypt packet error: cipher final failed
                

                Vendor: HP
                Version: P01 Ver. 02.50
                Release Date: Wed Jul 17 2024
                Boot Method: UEFI
                24.11-RELEASE (amd64)
                FreeBSD 15.0-CURRENT
                CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
                Current: 3606 MHz, Max: 3400 MHz
                4 CPUs : 1 package(s) x 4 core(s)

                1 Reply Last reply Reply Quote 0
                • manjotscM
                  manjotsc @johnpoz
                  last edited by

                  @johnpoz Update : The Issue is fixed now by re exporting the client profile and dns is also seems to be working.

                  Vendor: HP
                  Version: P01 Ver. 02.50
                  Release Date: Wed Jul 17 2024
                  Boot Method: UEFI
                  24.11-RELEASE (amd64)
                  FreeBSD 15.0-CURRENT
                  CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
                  Current: 3606 MHz, Max: 3400 MHz
                  4 CPUs : 1 package(s) x 4 core(s)

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.