• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

OpenVPN Connection Issues with PfSense - Default Gateway

Scheduled Pinned Locked Moved OpenVPN
4 Posts 2 Posters 178 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    thomalv
    last edited by Dec 23, 2024, 4:54 PM

    Hello everyone,

    I'm facing an issue when trying to connect to my OpenVPN server. The connection only works when the interface gateway is the default gateway of my PfSense.

    Has anyone faced this issue or have any suggestions on how to resolve it?

    Thanks for any help!

    V 1 Reply Last reply Dec 23, 2024, 9:24 PM Reply Quote 0
    • V
      viragomann @thomalv
      last edited by Dec 23, 2024, 9:24 PM

      @thomalv
      Can you give some more details an this, please?
      What do you mean with "when the interface gateway is the default gateway of my PfSense"?

      T 1 Reply Last reply Dec 23, 2024, 10:45 PM Reply Quote 0
      • T
        thomalv @viragomann
        last edited by Dec 23, 2024, 10:45 PM

        @viragomann
        Yes! I have two WANs configured in my pfSense. The OpenVPN server is set to connect through WAN2, while WAN1 is my default gateway.

        The issue is that the OpenVPN server only works if WAN2 is set as the default gateway on the firewall. Otherwise, it won't connect.

        V 1 Reply Last reply Dec 24, 2024, 9:29 AM Reply Quote 0
        • V
          viragomann @thomalv
          last edited by Dec 24, 2024, 9:29 AM

          @thomalv
          Add a rule to the WAN2 interface tab to allow access to the OpenVPN server, state a unique description and ensure, that it is applied to the incoming traffic to the server.

          Remove floating pass rules or pass rules on interface group tabs, which may match the OpenVPN traffic, if any.
          For connections passed by these rules, the reply-to isn't set. But it's required to send reply packets back to the correct gateway.

          Note that floating quick rules and interface group rules have precedence over member interface rules. So you have to ensure, that none of these match the VPN traffic.

          1 Reply Last reply Reply Quote 0
          3 out of 4
          • First post
            3/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received