Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Opnevpn client to site and change password domain user

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 3 Posters 778 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      miami71it
      last edited by

      hello everyone, I have a vpn on pfsense with OpeVpn configured client to site, and everything works perfectly, but I have a big problem, when Windows asks for a password change, if the windows pc is inside the company then connected to the domain it works but if the operator is at home working in smartworking then the password obviously doesn't change and it is changed only on the local PC and if I connect the vpn I don't see the network because the passwords don't match.
      how can i fix it? an openvpn I configured single users I have not connected the users on the domain, if I do this then the password change works when the vpn is connected?

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Can we assume OpenVPN is authenticating against AD and Windows password changes are supposed to be set there?
        This seems like something Windows would have to solve. And there probably is a solution already.

        M 1 Reply Last reply Reply Quote 0
        • M
          miami71it @stephenw10
          last edited by

          @stephenw10 hi thanks for the answer.
          No Openvpn authenticates via preconfigured users from system->user manager

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @miami71it
            last edited by

            @miami71it
            Is the domain controller even reachable over the VPN?

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Mmm, if this isn't a chicken/egg type problem then just allow remote hosts to connect to the DC. Changing the password on the client shouldn't prevent the VPN connecting if it's using a local user list.

              M 1 Reply Last reply Reply Quote 0
              • M
                miami71it @stephenw10
                last edited by

                @stephenw10 but the users are enabled, the PCs are all connected to a domain, when I'm in the office it works great, when I'm in smartworking it doesn't, because when they turn on the PC, Windows asks them to change their password but the connection to OpenVpn takes place after the change therefore windows locally changes the password but then they don't enter the network shares because the domain has not received the password change

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by stephenw10

                  Hmm, well that still sounds like a Windows problem. Nothing pfSense can do about that. I do recall some discussion of running the OpenVPN client as a service so it's connected before login. That should be here on the forum somewhere.

                  Edit: https://forum.netgate.com/post/969315

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.