Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN bad encapsulated packet length question

    Scheduled Pinned Locked Moved General pfSense Questions
    32 Posts 6 Posters 423 Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      amrogers3 @stephenw10
      last edited by

      @stephenw10

      That is interesting. So if I am not running a web server, I can just redirect to a IP to an internal IP that doesn't exist?

      I have a 192.168.1.x network but not 192.168.2.x.

      port-share 192.168.2.111 443;
      
      1 Reply Last reply Reply Quote 0
      • stephenw10S Online
        stephenw10 Netgate Administrator
        last edited by

        Yup you could though I'm not sure what advantage that might give.

        But I certainly wouldn't try that until you have a basic UDP server setup and working as expected. Any custom server config is likely to make diagnosing issue more difficult. Start simple, add fun stuff later! ๐Ÿ˜‰

        A 1 Reply Last reply Reply Quote 0
        • A Offline
          amrogers3 @stephenw10
          last edited by amrogers3

          @stephenw10

          I think I may be dealing with the issue @netblues mentioned that on one particular network, it is blocking VPN.

          I am not sure what that would look like in the logs but I can create a new post on the topic if that would be more appropriate. What would a Firewall block on VPN look like in the logs? Would it hang the connection? Would it look like this?
          It can find the VPN server but cannot connect.

          ffc5835c-5231-4770-bd2a-3435c8b50f21-image.png

          It then hangs on attempting to establish a TCP connection.

          My VPN is functional over other networks, this is the only network that is giving me issues.

          1 Reply Last reply Reply Quote 0
          • stephenw10S Online
            stephenw10 Netgate Administrator
            last edited by

            Yes you would likely just see no replies at all because the server never sees the incoming connection.

            A 1 Reply Last reply Reply Quote 0
            • A Offline
              amrogers3 @stephenw10
              last edited by

              @stephenw10

              Ok, I will do some research on VPN port share tonight and do some testing.

              1 Reply Last reply Reply Quote 0
              • stephenw10S Online
                stephenw10 Netgate Administrator
                last edited by

                I would not expect that to help in this situation, just FYI.

                1 Reply Last reply Reply Quote 0
                • A Offline
                  amrogers3
                  last edited by

                  Good to know. Is there a way around DPI?

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S Online
                    stephenw10 Netgate Administrator
                    last edited by

                    It depends. Probably not if it's any good. Not easily at least.

                    1 Reply Last reply Reply Quote 0
                    • A Offline
                      amrogers3
                      last edited by amrogers3

                      yep, looks like I am done. I checked 443 and 1194 from another network and both are connecting. The network I need openVPN to work appears to be blocking both ports. Port 443 wasn't working before so I gave 1194 a shot just to check if default was allowed, however, the firewall appears to also block 1194.
                      Bummer ๐Ÿ˜ข

                      Screenshot 2025-08-06 at 12.18.16 PM.png

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S Online
                        stephenw10 Netgate Administrator
                        last edited by

                        You can try something like UDP port 53 or 123 which are commonly passed. But you would need to do some shuffling for that since pfSense is already listening on those ports for DNS and NTP. You could forward traffic incoming on those to port 1194 on localhost for example.

                        A 1 Reply Last reply Reply Quote 0
                        • stephenw10S Online
                          stephenw10 Netgate Administrator
                          last edited by

                          Though 'no route to host' there could be a local networking issue rather than a firewall blocking anything.

                          1 Reply Last reply Reply Quote 0
                          • A Offline
                            amrogers3 @stephenw10
                            last edited by

                            @stephenw10

                            Thank you. I will do some research on this option

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.