• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

openvpn not working from local network

Scheduled Pinned Locked Moved OpenVPN
13 Posts 3 Posters 2.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    serj161
    last edited by Apr 15, 2023, 8:48 AM

    I have 2 wan interfaces. openvpn for 2 wan configured according to instructions - https://docs.netgate.com/pfsense/en/latest/multiwan/openvpn.html
    I can connect to the local network from external IP addresses, for example by distributing wifi from my phone. but at the same time I can connect to openvpn from the local network. when connecting, I get an error - 127.0.0.1:54796 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
    Apr 15 11:13:12 openvpn 34818 127.0.0.1:54796 TLS Error: TLS handshake failed

    G M 2 Replies Last reply Apr 15, 2023, 12:10 PM Reply Quote 0
    • G
      Gertjan @serj161
      last edited by Apr 15, 2023, 12:10 PM

      @serj161

      No need to use OpenVPN when you device (phone) is connected to the 'pfSense' local network.

      OpenVPN is only needed when you are outside, away from your network.
      OpenVPN conencts to your WAN(s) - that's where the OpenVPN are listening, and when authorized, you can acces your pfSense local network(s). Firewall rules still need to grant the access, though.

      @serj161 said in openvpn not working from local network:

      I get an error - 127.0.0.1:54796 TLS Error: TLS key negotiation

      At that moment, look at the pfSense OpenVPN server log.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      S 1 Reply Last reply Apr 15, 2023, 12:23 PM Reply Quote 0
      • S
        serj161 @Gertjan
        last edited by Apr 15, 2023, 12:23 PM

        @gertjan The fact is that I need to use a tablet with a sim to bypass the territory. not everywhere there is access to the local wifi network and it is very inconvenient to disconnect and connect to the VPN every time when the wifi signal is lost. the error I indicated was taken from the OpenVPN server log - Apr 15 15:22:42 openvpn 1071 127.0.0.1:8045 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
        Apr 15 15:22:42 openvpn 1071 127.0.0.1:8045 TLS Error: TLS handshake failed

        G 1 Reply Last reply Apr 15, 2023, 5:35 PM Reply Quote 0
        • G
          Gertjan @serj161
          last edited by Apr 15, 2023, 5:35 PM

          @serj161 said in openvpn not working from local network:

          127.0.0.1:8045

          I don't understand the context "127.0.0.1".
          This means the connection comes in at 127.0.0.1 : this means the OpenVPN client runs on pfSense itself ?
          Normally, a connection comes in the (a) WAN interface.

          I've selected :

          745b1a33-a5c4-4a83-ac12-89b0649aa4f6-image.png

          and still don't understand the subject "openvpn not working from local network".

          You've exported a opvpn config file with certificates, using OpenVPN > Client Export Utility, right ?

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          S 1 Reply Last reply Apr 17, 2023, 9:28 AM Reply Quote 0
          • M
            michmoor LAYER 8 Rebel Alliance @serj161
            last edited by Apr 15, 2023, 9:43 PM

            @serj161 So you use OpenVPN to bypass any GeoIP restrictions?
            Or are you trying to use OpenVPN for that use case? Its not really clear what it is you are asking.

            Firewall: NetGate,Palo Alto-VM,Juniper SRX
            Routing: Juniper, Arista, Cisco
            Switching: Juniper, Arista, Cisco
            Wireless: Unifi, Aruba IAP
            JNCIP,CCNP Enterprise

            1 Reply Last reply Reply Quote 0
            • S
              serj161
              last edited by Apr 17, 2023, 9:23 AM

              if 2 wan connections are used, then the settings were made according to this instruction - https://docs.netgate.com/pfsense/en/latest/multiwan/openvpn.html
              NAT
              d61ce944-a292-4454-a6d7-1f80ee49d3ad-image.png
              WAN1
              b9c13ccd-f56a-4961-b01c-3694f417b43b-image.png
              WAN2
              402a57a1-a20f-49d9-bc53-fd05b6b8495e-image.png

              1 Reply Last reply Reply Quote 0
              • S
                serj161 @Gertjan
                last edited by Apr 17, 2023, 9:28 AM

                @gertjan bee785d1-6f6d-40d8-bd22-d65744da9fde-image.png

                G 1 Reply Last reply Apr 17, 2023, 9:43 AM Reply Quote 0
                • G
                  Gertjan @serj161
                  last edited by Apr 17, 2023, 9:43 AM

                  @serj161

                  Ah, ok saw https://docs.netgate.com/pfsense/en/latest/multiwan/openvpn.html.

                  Using a NAT rule -> Redirecting to localhost is a thing when you use multiple WANs.
                  Is this so you can create a openvp client config that will use any of the available WANs ?

                  Does it work if you set up a classic : one openvpn server on one WAN, and a second openvpn server on the other WAN ? So no need to nat to 127.0.0.1.

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  S 1 Reply Last reply Apr 17, 2023, 9:58 AM Reply Quote 0
                  • S
                    serj161 @Gertjan
                    last edited by Apr 17, 2023, 9:58 AM

                    @gertjan
                    I use 1 VPN server, 2 remote connections are specified in the user config
                    3aeba41b-85d9-43c6-8daa-194d10a90a3a-image.png
                    86bae155-8865-4ae4-b757-437b9060cc7f-image.png

                    G 1 Reply Last reply Apr 17, 2023, 11:18 AM Reply Quote 0
                    • G
                      Gertjan @serj161
                      last edited by Gertjan Apr 17, 2023, 11:18 AM Apr 17, 2023, 11:18 AM

                      @serj161

                      I've set up my OpenVPN server like you :

                      486cccaf-db7b-48ee-821e-da1453ac1b9a-image.png

                      so now it listens to 127.0.0.1:1194 UDP.

                      I created a NAT rule (only one, as I have just one WAN) :

                      d3f89591-8932-4bfb-9b60-7d8ef9398feb-image.png

                      that redirects to 127.0.0.1:1194

                      A firewall was also created, as it is part of the NAT rule :

                      6dec768a-e4c7-4fe8-9cbb-0d114b93bc19-image.png

                      I've tested with my phone, and I can connect just fine to my pfSense OpenServer.

                      @serj161 said in openvpn not working from local network:

                      TLS Error: TLS key negotiation failed to occur within 60 seconds

                      https://openvpn.net/faq/tls-error-tls-key-negotiation-failed-to-occur-within-60-seconds-check-your-network-connectivity/
                      ? a generic 'network not ok', like upstream router not natted ?

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      S 1 Reply Last reply Apr 17, 2023, 12:16 PM Reply Quote 0
                      • S
                        serj161 @Gertjan
                        last edited by Apr 17, 2023, 12:16 PM

                        @gertjan
                        maybe I don't have enough outbound rules, can you show the rules in the "Outbound" tab for the VPN?

                        G 1 Reply Last reply Apr 17, 2023, 1:44 PM Reply Quote 0
                        • G
                          Gertjan @serj161
                          last edited by Apr 17, 2023, 1:44 PM

                          @serj161

                          Nothing to do over there for a VPN server :

                          01618f24-f325-4952-be6c-51c06672a1c8-image.png

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          S 1 Reply Last reply Apr 17, 2023, 1:50 PM Reply Quote 0
                          • S
                            serj161 @Gertjan
                            last edited by Apr 17, 2023, 1:50 PM

                            @gertjan
                            I agree, I have the same rules.
                            I'll try to return the default settings and configure a different vpn server for each interface. thank you for your help.

                            1 Reply Last reply Reply Quote 0
                            13 out of 13
                            • First post
                              13/13
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                              This community forum collects and processes your personal information.
                              consent.not_received