Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Privacy VPNs getting the same virtual IP-address

    Scheduled Pinned Locked Moved General pfSense Questions
    8 Posts 3 Posters 872 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Bob.DigB Offline
      Bob.Dig LAYER 8
      last edited by

      There is one annoyance if you have more than one Client to a privacy VPN in pfSense. There often is the chance that two or more Clients get the same virtual/tunnel IP-address (and gateway) from those VPN Providers and there is nothing one could do about that.

      What makes things worse is that Gateway Monitoring still works for those clients (status:online), so for me it seems to be only a routing problem.
      Thankfully pfSense is not routing traffic through the wrong gateway.
      But with policy based routing with a gateway defined by its name in a rule, it could technically still be routed the correct way?

      Anyways, what could be done to solve this problem for those few home users using these types of VPN-services? Those services mostly allow only some small number of concurrent connections, so they won't have any intend to fix it on their side, I guess.

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        No easy solution I'm aware of. None of the NAT options in OpenVPN apply to the tunnel subnet itself.

        You can often set a different server and get a different tunnel subnet.

        Some providers offer Wireguard or IPSec servers which might be an option.

        1 Reply Last reply Reply Quote 1
        • Bob.DigB Offline
          Bob.Dig LAYER 8
          last edited by

          Maybe someone has a watchdog script or something?
          I get it that this is not a typical problem for a "firewall".

          1 Reply Last reply Reply Quote 0
          • stephenw10S Offline
            stephenw10 Netgate Administrator
            last edited by

            A script to reconnect if it gets a conflicting tunnel subnet?

            Bob.DigB 1 Reply Last reply Reply Quote 0
            • Bob.DigB Offline
              Bob.Dig LAYER 8 @stephenw10
              last edited by

              @stephenw10 said in Privacy VPNs getting the same virtual IP-address:

              A script to reconnect if it gets a conflicting tunnel subnet?

              Yeah, you got one? ๐Ÿค”

              1 Reply Last reply Reply Quote 0
              • stephenw10S Offline
                stephenw10 Netgate Administrator
                last edited by

                Nope. ๐Ÿ˜‰
                I am discovering it's a problem that's almost impossible to Google for though...

                NogBadTheBadN 1 Reply Last reply Reply Quote 0
                • NogBadTheBadN Offline
                  NogBadTheBad @stephenw10
                  last edited by NogBadTheBad

                  NordVPN seem to use the same configs for all the VPN servers, I set up 3 ( in different regions ) to play with gateway groups and noticed quite often some of the addresses handed out to clients only vary by the last octet.

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  Bob.DigB 1 Reply Last reply Reply Quote 0
                  • Bob.DigB Offline
                    Bob.Dig LAYER 8 @NogBadTheBad
                    last edited by

                    @nogbadthebad Only the last octet is changing and mostly it is just 1-9 for me.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.