Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Privacy VPNs getting the same virtual IP-address

    Scheduled Pinned Locked Moved General pfSense Questions
    8 Posts 3 Posters 740 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Bob.DigB
      Bob.Dig LAYER 8
      last edited by

      There is one annoyance if you have more than one Client to a privacy VPN in pfSense. There often is the chance that two or more Clients get the same virtual/tunnel IP-address (and gateway) from those VPN Providers and there is nothing one could do about that.

      What makes things worse is that Gateway Monitoring still works for those clients (status:online), so for me it seems to be only a routing problem.
      Thankfully pfSense is not routing traffic through the wrong gateway.
      But with policy based routing with a gateway defined by its name in a rule, it could technically still be routed the correct way?

      Anyways, what could be done to solve this problem for those few home users using these types of VPN-services? Those services mostly allow only some small number of concurrent connections, so they won't have any intend to fix it on their side, I guess.

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        No easy solution I'm aware of. None of the NAT options in OpenVPN apply to the tunnel subnet itself.

        You can often set a different server and get a different tunnel subnet.

        Some providers offer Wireguard or IPSec servers which might be an option.

        1 Reply Last reply Reply Quote 1
        • Bob.DigB
          Bob.Dig LAYER 8
          last edited by

          Maybe someone has a watchdog script or something?
          I get it that this is not a typical problem for a "firewall".

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            A script to reconnect if it gets a conflicting tunnel subnet?

            Bob.DigB 1 Reply Last reply Reply Quote 0
            • Bob.DigB
              Bob.Dig LAYER 8 @stephenw10
              last edited by

              @stephenw10 said in Privacy VPNs getting the same virtual IP-address:

              A script to reconnect if it gets a conflicting tunnel subnet?

              Yeah, you got one? 🤔

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Nope. 😉
                I am discovering it's a problem that's almost impossible to Google for though...

                NogBadTheBadN 1 Reply Last reply Reply Quote 0
                • NogBadTheBadN
                  NogBadTheBad @stephenw10
                  last edited by NogBadTheBad

                  NordVPN seem to use the same configs for all the VPN servers, I set up 3 ( in different regions ) to play with gateway groups and noticed quite often some of the addresses handed out to clients only vary by the last octet.

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  Bob.DigB 1 Reply Last reply Reply Quote 0
                  • Bob.DigB
                    Bob.Dig LAYER 8 @NogBadTheBad
                    last edited by

                    @nogbadthebad Only the last octet is changing and mostly it is just 1-9 for me.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.