• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Problem with Virtual Address

Scheduled Pinned Locked Moved OpenVPN
11 Posts 5 Posters 944 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • E
    eduardoeller
    last edited by Jun 29, 2022, 1:38 PM

    I have a lab with 50 virtual machines, I would like each of them to have an output ip using the SurfShark service.
    For that I did the configuration via OpenVPN Client, I created rules on the LAN so that each machine had its own gateway.
    The problem occurs when the OpenVPN client receives the same virtual address.
    I tried in several ways to solve this problem but I couldn't.
    I keep restarting the openvpn client connection but it always gets the same ip.

    gateway.png
    virtual_address.png

    Need help.

    J V 2 Replies Last reply Jun 29, 2022, 4:01 PM Reply Quote 0
    • J
      JKnott @eduardoeller
      last edited by Jun 29, 2022, 4:01 PM

      @eduardoeller

      You can't assign the same address to more than one device. Is the OpenVPN tunnel in the same subnet?

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      E 1 Reply Last reply Jun 29, 2022, 4:06 PM Reply Quote 0
      • E
        eduardoeller @JKnott
        last edited by Jun 29, 2022, 4:06 PM

        @jknott I use SurfShark VPN, I don't know how to solve the virtual address problem

        1 Reply Last reply Reply Quote 0
        • V
          viragomann @eduardoeller
          last edited by Jun 29, 2022, 4:53 PM

          @eduardoeller
          So you have 50 Surfshark clients?

          It's on the VPN server to assign a virtual IP to the client. There is nothing you can do on the client side the change it.

          Contact Surfshark and tell them your problem.

          E 1 Reply Last reply Jun 29, 2022, 4:56 PM Reply Quote 0
          • E
            eduardoeller @viragomann
            last edited by Jun 29, 2022, 4:56 PM

            @viragomann I tried to talk to them, I tried to change the certificates, but it keeps getting the same virtual address, I don't know what to do, they told me to contact netgate, that's why I'm here

            V 1 Reply Last reply Jun 29, 2022, 5:02 PM Reply Quote 0
            • V
              viragomann @eduardoeller
              last edited by Jun 29, 2022, 5:02 PM

              @eduardoeller
              No, as mentioned, the clients virtual IP is given by the server. You cannot change it. If you try to do that the server will drop the connection.

              E N 2 Replies Last reply Jun 29, 2022, 5:06 PM Reply Quote 0
              • E
                eduardoeller @viragomann
                last edited by Jun 29, 2022, 5:06 PM

                @viragomann Is there any rule, certificate, anything I can do to make pfsense work with the duplicate ip?

                V 1 Reply Last reply Jun 29, 2022, 5:26 PM Reply Quote 0
                • V
                  viragomann @eduardoeller
                  last edited by Jun 29, 2022, 5:26 PM

                  @eduardoeller
                  No, the real problem isn't the duplicated clients IPs, but the duplicated virtual server IPs, which pfSense needs as gateway for routing the traffic.

                  Since the clients IPs are duplicated, the servers will have equal configurations and hence provide the same gateway IPs to multiple clients. Consequently pfSense will not be able to route the traffic to the different VPN servers as they are using the same virtual IP.

                  1 Reply Last reply Reply Quote 0
                  • N
                    NogBadTheBad @viragomann
                    last edited by NogBadTheBad Jun 29, 2022, 6:19 PM Jun 29, 2022, 6:17 PM

                    @viragomann said in Problem with Virtual Address:

                    @eduardoeller
                    No, as mentioned, the clients virtual IP is given by the server. You cannot change it. If you try to do that the server will drop the connection.

                    Since the clients IPs are duplicated, the servers will have equal configurations and hence provide the same gateway IPs to multiple clients. Consequently pfSense will not be able to route the traffic to the different VPN servers as they are using the same virtual IP.

                    ^^ This it's the same with NordVPN, they have the same configs on their VPN servers that hand out the same address range to the clients, they don't account for multi VPN connections.

                    I'm at a loss why Surfshark said talk to Netgate ...

                    Andy

                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                    J V 2 Replies Last reply Jun 29, 2022, 6:54 PM Reply Quote 0
                    • J
                      johnpoz LAYER 8 Global Moderator @NogBadTheBad
                      last edited by Jun 29, 2022, 6:54 PM

                      @nogbadthebad said in Problem with Virtual Address:

                      I'm at a loss why Surfshark said talk to Netgate ...

                      Because as most services - pass the buck..

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      1 Reply Last reply Reply Quote 1
                      • V
                        viragomann @NogBadTheBad
                        last edited by Jun 29, 2022, 6:55 PM

                        @nogbadthebad said in Problem with Virtual Address:

                        I'm at a loss why Surfshark said talk to Netgate ...

                        Because that’s an easy way for the first level support to get rid of an onerous customer.

                        1 Reply Last reply Reply Quote 2
                        1 out of 11
                        • First post
                          1/11
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                          This community forum collects and processes your personal information.
                          consent.not_received