Upgrading from 2.6.0 to latest community version(2.7.2)
-
Good day everyone,
Hope you're all doing well. I am planning to upgrade our production Pfsense community edition firewall and I'm hesitant because I'm not sure that all will go well on openvpn side as I have read there are changes in encryption algorithms being deprecated. We currently have almost 30 openvpn instances running on this router: Remote access VPN and pre shared key site to site. Just want to confirm if I will be having problems with my current openvpn setup if we upgrade to 2.7.2 Community.
Thank you.
-
@rjabellax5
Basically your settings should also work well with pfSense 2.7.2.
However, shared key mode will be removed from future OpenVPN versions. So you should consider to move over to SSL/TLS peer-to-peer connections.
At this occasion you may also want to update the ciphers to GCM or CHACHA20-POLY1305, depending on your hardware.