<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenVPN connection fails unless appliance has static IP WAN]]></title><description><![CDATA[[[topic:post-is-deleted]]]]></description><link>https://forum.netgate.com/topic/165528/openvpn-connection-fails-unless-appliance-has-static-ip-wan</link><generator>RSS for Node</generator><lastBuildDate>Wed, 20 May 2026 06:56:38 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/165528.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 31 Jul 2021 16:57:01 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to OpenVPN connection fails unless appliance has static IP WAN on Mon, 02 Aug 2021 01:26:41 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/abinition">@<bdi>abinition</bdi></a> said in <a href="/post/994943">OpenVPN connection fails unless appliance has static IP WAN</a>:</p>
<blockquote>
<p dir="auto">Away you go...</p>
</blockquote>
<p dir="auto">What about IPv6?</p>
]]></description><link>https://forum.netgate.com/post/994949</link><guid isPermaLink="true">https://forum.netgate.com/post/994949</guid><dc:creator><![CDATA[JKnott]]></dc:creator><pubDate>Mon, 02 Aug 2021 01:26:41 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN connection fails unless appliance has static IP WAN on Mon, 02 Aug 2021 00:25:56 GMT]]></title><description><![CDATA[<p dir="auto">Solved!</p>
<p dir="auto">For those with ATT Uverse Arris NVG599 router and a block of 5 static IP's, the key to getting OpenVPN to connect is as follows:</p>
<ol>
<li>Leave WAN interface in DHCP mode. Ex: 192.168.1.199</li>
<li>Add a static route for the x.y.z.48/29 network</li>
<li>Add 5 CARP VIP's 49,50,51,52,53</li>
<li>Use OpenVPN wizard to generate WAN address service</li>
<li>Confirm RULE also written for port 1194 WAN address</li>
<li>Add NAT to translate x.y.z.53 for port 1194 to WAN address 192.168.1.99</li>
<li>Export openvpn config.</li>
<li>Edit the config and change 192.168.1.199 to x.y.z.53</li>
</ol>
<p dir="auto">Away you go...</p>
]]></description><link>https://forum.netgate.com/post/994943</link><guid isPermaLink="true">https://forum.netgate.com/post/994943</guid><dc:creator><![CDATA[abinition]]></dc:creator><pubDate>Mon, 02 Aug 2021 00:25:56 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN connection fails unless appliance has static IP WAN on Sun, 01 Aug 2021 20:47:47 GMT]]></title><description><![CDATA[<p dir="auto">I stand corrected: the WAN setting via the console or via the web gui are the same thing.</p>
<p dir="auto">But, the provider router is an ATT Uverse Arris NVG599.  It can be a DHCP server of the static sub-net, so it can assign the pfsense router one of those static IPs.   When that happens, how I don't know exactly, things will work great, including openvpn.</p>
<p dir="auto">But if the pfsense appliance get's assigned a 192.168 DHCP IP, then there seems no way to contact the OpenVPN server.  But all the CARP VIP's work just great.</p>
<p dir="auto">If the pfsense is assigned one of the static IPs, then no remote connections, including HTTP,SSH,OpenVPN seem to get thru on the other VIPs.</p>
<p dir="auto">Maybe tell the NVG599 router about the mac address of the pfsense appliance and have it allocated one of the static IPs to that.</p>
]]></description><link>https://forum.netgate.com/post/994921</link><guid isPermaLink="true">https://forum.netgate.com/post/994921</guid><dc:creator><![CDATA[abinition]]></dc:creator><pubDate>Sun, 01 Aug 2021 20:47:47 GMT</pubDate></item></channel></rss>