Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN connection fails unless appliance has static IP WAN

    OpenVPN
    2
    4
    373
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      abinition
      last edited by

      This post is deleted!
      1 Reply Last reply Reply Quote 0
      • A
        abinition
        last edited by

        I stand corrected: the WAN setting via the console or via the web gui are the same thing.

        But, the provider router is an ATT Uverse Arris NVG599. It can be a DHCP server of the static sub-net, so it can assign the pfsense router one of those static IPs. When that happens, how I don't know exactly, things will work great, including openvpn.

        But if the pfsense appliance get's assigned a 192.168 DHCP IP, then there seems no way to contact the OpenVPN server. But all the CARP VIP's work just great.

        If the pfsense is assigned one of the static IPs, then no remote connections, including HTTP,SSH,OpenVPN seem to get thru on the other VIPs.

        Maybe tell the NVG599 router about the mac address of the pfsense appliance and have it allocated one of the static IPs to that.

        1 Reply Last reply Reply Quote 0
        • A
          abinition
          last edited by

          Solved!

          For those with ATT Uverse Arris NVG599 router and a block of 5 static IP's, the key to getting OpenVPN to connect is as follows:

          1. Leave WAN interface in DHCP mode. Ex: 192.168.1.199
          2. Add a static route for the x.y.z.48/29 network
          3. Add 5 CARP VIP's 49,50,51,52,53
          4. Use OpenVPN wizard to generate WAN address service
          5. Confirm RULE also written for port 1194 WAN address
          6. Add NAT to translate x.y.z.53 for port 1194 to WAN address 192.168.1.99
          7. Export openvpn config.
          8. Edit the config and change 192.168.1.199 to x.y.z.53

          Away you go...

          JKnottJ 1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @abinition
            last edited by

            @abinition said in OpenVPN connection fails unless appliance has static IP WAN:

            Away you go...

            What about IPv6?

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.