• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

pfSense OpenVPN on VPS client not access internet

Scheduled Pinned Locked Moved OpenVPN
openvpn
15 Posts 3 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    romanvekil
    last edited by romanvekil Sep 22, 2021, 12:22 PM Sep 22, 2021, 12:02 PM

    i installed pfSense on VPS and configure OpenVPN. client config connecting to server but not coming "Bytes in 0". no internet access
    after 60 sec reconnecting.
    please help what is wrong? here config files drom pfsense
    openvpn-config-pfSense.localdomain-20210922120015.xml nat-config-pfSense.localdomain-20210922120020.xml filter-config-pfSense.localdomain-20210922120026.xml staticroutes-config-pfSense.localdomain-20210922120035.xml interfaces-config-pfSnse.localdomain-20210922120042.xml

    and user config
    1pfSense-UDP4-443-123-config (4).txt

    8sСнимок.JPG 7sСнимок.JPG 6sСнимок.JPG 5sСнимок.JPG 4sСнимок.JPG 3sСнимок.JPG 2sСнимок.JPG 1sСнимок.JPG
    4Снимок.JPG 3Снимок.JPG 2Снимок.JPG 1Снимок.JPG

    V 1 Reply Last reply Sep 22, 2021, 12:33 PM Reply Quote 0
    • V
      viragomann @romanvekil
      last edited by Sep 22, 2021, 12:33 PM

      @romanvekil
      There is no need to add static routes. Set the WAN gateway as default, no other settings needed.

      As well there is no need to set the outbound NAT to manual rules generation. Use the hybrid mode.

      Something in the logs on client or server?

      R 2 Replies Last reply Sep 22, 2021, 12:42 PM Reply Quote 0
      • R
        romanvekil @viragomann
        last edited by Sep 22, 2021, 12:42 PM

        @viragomann here client logs 1kСнимок.JPG [0_1632314539228_OpenVPN-client.log](Uploading 100%) OpenVPN-client.txt

        V 1 Reply Last reply Sep 22, 2021, 12:56 PM Reply Quote 0
        • R
          romanvekil @viragomann
          last edited by Sep 22, 2021, 12:46 PM

          @viragomann said in pfSense OpenVPN on VPS client not access internet:

          Set the WAN gateway as default

          how to set it as default?

          R 1 Reply Last reply Sep 22, 2021, 12:49 PM Reply Quote 0
          • R
            romanvekil @romanvekil
            last edited by Sep 22, 2021, 12:49 PM

            @romanvekil GATСнимок.JPG

            V 1 Reply Last reply Sep 22, 2021, 12:52 PM Reply Quote 0
            • V
              viragomann @romanvekil
              last edited by Sep 22, 2021, 12:52 PM

              @romanvekil
              Exactly.

              1 Reply Last reply Reply Quote 0
              • V
                viragomann @romanvekil
                last edited by Sep 22, 2021, 12:56 PM

                @romanvekil
                So your client connects successfully and routes all upstream traffic to the VPN server.

                The outbound NAT shown in your screenshot is necessary at all, but use the hybrid mode so that automatically generated rules are still active.

                So what's the problem now?
                If you are not able to access the internet ensure that DNS resolution is working on the client.

                R 1 Reply Last reply Sep 22, 2021, 1:00 PM Reply Quote 0
                • R
                  romanvekil @viragomann
                  last edited by Sep 22, 2021, 1:00 PM

                  @viragomann NATСнимок.JPG

                  i did it but not helped
                  thanks very much for your answers

                  R 1 Reply Last reply Sep 23, 2021, 8:58 AM Reply Quote 0
                  • R
                    romanvekil @romanvekil
                    last edited by Sep 23, 2021, 8:58 AM

                    @romanvekil User connecting but Bytes in is 0 there is not coming traffic from server

                    V 1 Reply Last reply Sep 23, 2021, 10:49 AM Reply Quote 0
                    • V
                      viragomann @romanvekil
                      last edited by Sep 23, 2021, 10:49 AM

                      @romanvekil said in pfSense OpenVPN on VPS client not access internet:
                      User connecting but Bytes in is 0 there is not coming traffic from server

                      Yes, I can see that the connection succeed as I mentioned. But 0 Bytes in is not really a good hint for what's wrong.
                      You will have to investigate your issue.

                      I already requested you to find out if the DNS resolution is working on the client. I assume, the browser doesn't load any page. So simply type in "1.1.1.1" in the browsers to check if it works with IP directly.

                      Did you try a connection also from another client?

                      R 2 Replies Last reply Sep 23, 2021, 1:03 PM Reply Quote 0
                      • R
                        romanvekil @viragomann
                        last edited by Sep 23, 2021, 1:03 PM

                        @viragomann yes it not working even if directly write ip to browser. and even ping to 10.8.0.1 not going only pinging it self

                        1 Reply Last reply Reply Quote 0
                        • R
                          romanvekil @viragomann
                          last edited by Sep 23, 2021, 1:54 PM

                          @viragomann
                          pfTop: Up State 1-24/24, View: default, Order: bytes
                          PR DIR SRC DEST STATE AGE EXP PKTS BYTES
                          icmp Out 10.8.0.1:57465 10.8.0.1:57465 0:0 04:07:57 00:00:10 110423 3202267
                          icmp Out 5.135.121.51:61483 8.8.8.8:61483 0:0 04:07:57 00:00:10 55840 1619360
                          udp In 217.174.225.106:15670 5.135.121.51:443 MULTIPLE:MULTIPLE 00:01:14 00:00:58 36 11077

                          V 1 Reply Last reply Sep 23, 2021, 2:22 PM Reply Quote 0
                          • V
                            viragomann @romanvekil
                            last edited by Sep 23, 2021, 2:22 PM

                            @romanvekil
                            So there is a UDP connection to your WAN on 443 showing some Bytes.

                            Possibly sniffing the traffic is more helpful using the packet capture tool.
                            You can for instance capture the traffic on the OpenVPN interface filtering for host 8.8.8.8 and ICMP protocol, while you try to ping 8.8.8.8. If you can see the ICMP packets sniff on the WAN and try again.

                            R 1 Reply Last reply Sep 23, 2021, 3:29 PM Reply Quote 0
                            • R
                              romanvekil @viragomann
                              last edited by romanvekil Sep 23, 2021, 3:35 PM Sep 23, 2021, 3:29 PM

                              @viragomann
                              pingСнимок.JPG

                              here wireshark listening vpn interface form pc when connected
                              here is only one direction traffic from pc to vpn server but back nothing coming
                              even when i ping the 10.8.0.1 no answer
                              dns queries also no answers
                              aa14508c-d3c1-47dd-ba7a-38226afc0a73-ping2Снимок.JPG

                              V 1 Reply Last reply Sep 23, 2021, 4:45 PM Reply Quote 0
                              • V
                                viragomann @romanvekil
                                last edited by Sep 23, 2021, 4:45 PM

                                @romanvekil said in pfSense OpenVPN on VPS client not access internet:

                                here wireshark listening vpn interface form pc when connected

                                Would like to know if you can see these packets on pfSense OpenVPN interface likewise. I suspect, you can't.
                                In this case, I'd recommend to tear down the OpenVPN server and start from scratch.
                                Have read some threads here in the past, where people complaining similar issues and never got it working.

                                1 Reply Last reply Reply Quote 0
                                1 out of 15
                                • First post
                                  1/15
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                  This community forum collects and processes your personal information.
                                  consent.not_received