• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

NordVPN using OpenVPN not connecting

Scheduled Pinned Locked Moved OpenVPN
9 Posts 4 Posters 1.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    mradell
    last edited by Jul 26, 2022, 1:26 AM

    Hey all. I'm new to pfsSnse and trying to get my NordVPN working with pfSense 2.6. I followed the directions here (https://support.nordvpn.com/Connectivity/Router/1626958942/pfSense-2-5-Setup-with-NordVPN.htm). After it didn't work the first time I reset back to Factory Default and tried again, no luck. I've tried with 3 different servers, restarted the OpenVPN service, retraced my steps, etc, etc, with no luck. The OpenVPN status is always down.

    My outbound topology looks like this:

    pfSense (guest VM on ESXi host) -> WAN Interface -> ISP Router (In passthrough) -> Internet

    My inbound topology looks like this:

    Internet -> ISP Router (in passthrough) -> LAN Interface -> pfSense (guest VM on ESXi host)

    I have turned off the firewall on my ISP router. The TPLink router is in AP Mode and just acting as a ethernet switch/wireless AP with no firewall. I also tried disabling the ESXi firewall on my vm host.

    A packet capture from pfSense shows the following:

    pcap.jpg

    The source IP is my WAN interface. My public IP in this case as my ISP router is in IP Passthrough

    OpenVPN logs show me:

    Jul 26 01:12:49	openvpn	47018	OpenVPN 2.5.4 amd64-portbld-freebsd12.3 [SSL (OpenSSL)] [LZO] [LZ4] [MH/RECVDA] [AEAD] built on Jan 12 2022
    Jul 26 01:12:49	openvpn	47018	library versions: OpenSSL 1.1.1l-freebsd 24 Aug 2021, LZO 2.10
    Jul 26 01:12:49	openvpn	47023	MANAGEMENT: unix domain socket listening on /var/etc/openvpn/client1/sock
    Jul 26 01:12:49	openvpn	47023	NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
    Jul 26 01:12:49	openvpn	47023	WARNING: experimental option --capath /var/etc/openvpn/client1/ca
    Jul 26 01:12:49	openvpn	47023	Outgoing Control Channel Authentication: Using 256 bit message hash 'SHA256' for HMAC authentication
    Jul 26 01:12:49	openvpn	47023	Incoming Control Channel Authentication: Using 256 bit message hash 'SHA256' for HMAC authentication
    Jul 26 01:12:49	openvpn	47023	Control Channel MTU parms [ L:1653 D:1172 EF:78 EB:0 ET:0 EL:3 ]
    Jul 26 01:12:49	openvpn	47023	Data Channel MTU parms [ L:1653 D:1450 EF:121 EB:411 ET:32 EL:3 ]
    Jul 26 01:12:49	openvpn	47023	Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 1601,tun-mtu 1532,proto UDPv4,keydir 1,cipher AES-256-CBC,auth SHA256,keysize 256,tls-auth,key-method 2,tls-client'
    Jul 26 01:12:49	openvpn	47023	Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 1601,tun-mtu 1532,proto UDPv4,keydir 0,cipher AES-256-CBC,auth SHA256,keysize 256,tls-auth,key-method 2,tls-server'
    Jul 26 01:12:49	openvpn	47023	TCP/UDP: Preserving recently used remote address: [AF_INET]92.119.17.78:1194
    Jul 26 01:12:49	openvpn	47023	Socket Buffers: R=[42080->42080] S=[57344->57344]
    Jul 26 01:12:49	openvpn	47023	UDPv4 link local (bound): [AF_INET]104.52.211.159:0
    Jul 26 01:12:49	openvpn	47023	UDPv4 link remote: [AF_INET]92.119.17.78:1194
    Jul 26 01:12:54	openvpn	47023	MANAGEMENT: Client connected from /var/etc/openvpn/client1/sock
    Jul 26 01:12:54	openvpn	47023	MANAGEMENT: CMD 'state 1'
    Jul 26 01:12:54	openvpn	47023	MANAGEMENT: Client disconnected
    Jul 26 01:12:55	openvpn	47023	MANAGEMENT: Client connected from /var/etc/openvpn/client1/sock
    Jul 26 01:12:55	openvpn	47023	MANAGEMENT: CMD 'state 1'
    Jul 26 01:12:55	openvpn	47023	MANAGEMENT: Client disconnected
    Jul 26 01:12:55	openvpn	47023	MANAGEMENT: Client connected from /var/etc/openvpn/client1/sock
    Jul 26 01:12:55	openvpn	47023	MANAGEMENT: CMD 'state 1'
    Jul 26 01:12:55	openvpn	47023	MANAGEMENT: Client disconnected
    Jul 26 01:12:56	openvpn	47023	MANAGEMENT: Client connected from /var/etc/openvpn/client1/sock
    Jul 26 01:12:56	openvpn	47023	MANAGEMENT: CMD 'state 1'
    Jul 26 01:12:56	openvpn	47023	MANAGEMENT: Client disconnected
    

    Not too sure where to go from here. I have Googled a good bit and have not been able to find any solid answers. Any help is appreciated. Thanks.

    V 1 Reply Last reply Jul 26, 2022, 10:29 AM Reply Quote 0
    • V
      viragomann @mradell
      last edited by Jul 26, 2022, 10:29 AM

      @mradell
      Is your pfSense able to reach anything in the internet at all?
      For instance, when you ping 8.8.8.8, do you get a response?

      M 1 Reply Last reply Jul 26, 2022, 11:10 AM Reply Quote 1
      • M
        mradell @viragomann
        last edited by Jul 26, 2022, 11:10 AM

        @viragomann

        Yes. Ping works when Source address is set to Automatically selected (default), LAN, WAN, and out the NordVPN interface I created following the previous instructions I mentioned.

        25f8605a-f379-4843-b4db-d6c07bf971e5-image.png

        M 1 Reply Last reply Jul 27, 2022, 12:04 AM Reply Quote 0
        • M
          mradell @mradell
          last edited by Jul 27, 2022, 12:04 AM

          So I downloaded the OpenVPN Client for Windows on my PC that's behind pfSense in the LAN. I downloaded the config file for the same server I am trying to connect to in pfSense, same protocol (UDP), and it connects just fine from my PC through pfSense and out the WAN. This leads me to believe I must have something configured incorrectly in pfSense, but I'm really not sure what as I followed the directions provided exactly. I'll play around with some config, but I'm open to suggestions. Thanks.

          B G 2 Replies Last reply Jul 27, 2022, 7:20 AM Reply Quote 0
          • B
            Bob.Dig LAYER 8 @mradell
            last edited by Bob.Dig Jul 27, 2022, 8:07 AM Jul 27, 2022, 7:20 AM

            @mradell For a start, post screenshots of everything you have done to configure the vpn service. Is everything else working without the vpn service.

            M 2 Replies Last reply Jul 27, 2022, 10:17 PM Reply Quote 1
            • G
              Gertjan @mradell
              last edited by Jul 27, 2022, 7:45 AM

              @mradell said in NordVPN using OpenVPN not connecting:

              So I downloaded the OpenVPN Client for Windows on my PC that's behind pfSense in the LAN. I downloaded the config file for the same server I am trying to connect to in pfSense, same protocol (UDP), and it connects just fine from my PC through pfSense and out the WAN.

              Don't test OpenVPN from behind pfSense on one of it's LAN's. It might work (but who cares) : testing from the outside is far better.
              Take any smart 'phone', install the OpenVPN app, like this one. Samsung (android) and other clone phone also have the same app.

              If possible, check if the openVPN app you use is based on the same OpenVPN server version that pfSense is using.
              22.05 is using OpenVPN 2.5.4 - as does pfSense 2.6.0.
              Your client might be using 2.4.x. That can still work, but you need to read about version differences.

              Create an OpenVPN client account for your phone.
              Now use your phone to test.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 0
              • M
                mradell @Bob.Dig
                last edited by Jul 27, 2022, 10:17 PM

                This post is deleted!
                1 Reply Last reply Reply Quote 0
                • M
                  mradell @Bob.Dig
                  last edited by Jul 27, 2022, 11:30 PM

                  @bob-dig

                  So I went through the setup a third time and was taking screenshots of each step. As I was adding the OpenVPN client I noticed that I had the wrong 'Auth digest algorithm'...

                  49e53eea-7462-4713-b21b-abfe0d8311f9-image.png

                  I corrected this and finished the config...

                  cabb786e-8b30-4ba2-86c5-53cf7f55e8db-image.png

                  Now it works...

                  c3a42064-5d07-429f-a3a9-35cbb36e6b40-image.png

                  That's what happens when you just don't pay as close enough attention to detail as you think you did. Thanks everyone for your responses and for trying to help.

                  B 1 Reply Last reply Jul 28, 2022, 6:12 AM Reply Quote 0
                  • B
                    Bob.Dig LAYER 8 @mradell
                    last edited by Jul 28, 2022, 6:12 AM

                    @mradell said in NordVPN using OpenVPN not connecting:

                    That's what happens when you just don't pay as close enough attention to detail as you think you did.

                    Happens to all of us. 😉

                    1 Reply Last reply Reply Quote 0
                    9 out of 9
                    • First post
                      9/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received