• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

OpenVPN clients problems

Scheduled Pinned Locked Moved Routing and Multi WAN
7 Posts 3 Posters 899 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • U
    Uzzi78
    last edited by Jan 11, 2022, 8:47 AM

    Hi, i've a new pfsese installation.
    wan--->external Fortigate--->internet
    lan---->internal subnets
    Openvpn server on pfsense

    All openvpn clients, are negotiating correctily with server, but cannot navigate to internals subnets.
    Where can I see why? Firewall logs aren't helping me.
    What could be the problem?

    Thank you

    G 1 Reply Last reply Jan 11, 2022, 9:35 AM Reply Quote 0
    • G
      Gertjan @Uzzi78
      last edited by Jan 11, 2022, 9:35 AM

      @uzzi78

      @uzzi78 said in OpenVPN clients problems:

      Firewall logs aren't helping me.

      Maybe they could, if you let them do so.

      During test phase, check this option :

      67423fb3-ac85-4d07-8b3d-d18426c98239-image.png

      Now default (hidden) block rules will also log.
      Test again with a VPN client. Can you see traffic (being blocked) now in the firewall log ?

      @uzzi78 said in OpenVPN clients problems:

      but cannot navigate to internals subnets

      No access to LANs - but can you access for example the pfSense admin interface ?
      The internet ?

      Do you use this "OpenVPN" interface :

      72ae657d-7937-4096-b139-651554d19e73-image.png

      Or have you assigned to the OpenVPN server interface an interface (mine is called OPENVPN here ) :

      0582c640-d117-4338-8e0f-3ab2bb7cdb1b-image.png

      On the interface used by the OpenVPN server, as it is an 'incoming' interface' there must be pass rules. I've entered a pass for IPv4 and IPv65, as i'm using both.

      Also : check your clients, for what OpenVPN version they are using.
      pfSense 2.5.2 is based on the "2.5.2" OpenVPN version. There are some minor changes, when compared to the older 2.4.x OpenVPN that was used before.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      U 1 Reply Last reply Jan 11, 2022, 10:09 AM Reply Quote 0
      • U
        Uzzi78 @Gertjan
        last edited by Jan 11, 2022, 10:09 AM

        Hi @gertjan , thank you

        I'm tryng to ping 172.16.6.111 from OpenVPN clients
        I have disabled Log firewall default bloks
        Schermata da 2022-01-11 10-56-18.png

        Schermata da 2022-01-11 11-00-36.png

        J 1 Reply Last reply Jan 11, 2022, 10:15 AM Reply Quote 0
        • J
          johnpoz LAYER 8 Global Moderator @Uzzi78
          last edited by Jan 11, 2022, 10:15 AM

          @uzzi78 prob have compression setup wrong, not matching. Do you have comp-lzo set different on server vs client.. Compression really shouldn't be used currently.

          https://community.openvpn.net/openvpn/wiki/VORACLE

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          U 1 Reply Last reply Jan 11, 2022, 11:11 AM Reply Quote 0
          • U
            Uzzi78 @johnpoz
            last edited by Jan 11, 2022, 11:11 AM

            Thank you, now works fine.
            Can I notify when Openvpn clients are connected to server?

            J 1 Reply Last reply Jan 11, 2022, 11:26 AM Reply Quote 0
            • J
              johnpoz LAYER 8 Global Moderator @Uzzi78
              last edited by Jan 11, 2022, 11:26 AM

              @uzzi78 how you mean notify - you can see right on the dashboard if clients are connected, etc.

              Just add the openvpn widget

              Are you looking for like an email? here is thread

              https://forum.netgate.com/topic/151351/email-notification-openvpn-client-connect-common-name/26

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              U 1 Reply Last reply Jan 11, 2022, 5:15 PM Reply Quote 0
              • U
                Uzzi78 @johnpoz
                last edited by Jan 11, 2022, 5:15 PM

                Thank you
                works fine

                1 Reply Last reply Reply Quote 0
                7 out of 7
                • First post
                  7/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received