Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Site To Site and Road warrior in 2.0RCX

    OpenVPN
    2
    4
    2.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • perikoP
      periko
      last edited by

      Hi.

      With pfsense 1.2.3 I setup my server for a Road-Warrior and work, I remember that I had to user easy-rsa tools to build my files for each client. But now with pfsense 2.0 we have the certificate manager.

      For the Road warrior, do we still need the easy-rsa tools or we can use the certificate manager to build the keys for each client?

      Last thing, to connect 3 sites(networks) which setup is more strong against attacks:PKI or Shared Key?

      The pfsense machines are protect against physical intruders.

      Any input will be appreciated, thanks  :)

      Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
      www.bajaopensolutions.com
      https://www.facebook.com/BajaOpenSolutions
      Quieres aprender PfSense, visita mi canal de youtube:
      https://www.youtube.com/c/PedroMorenoBOS

      1 Reply Last reply Reply Quote 0
      • M
        Metu69salemi
        last edited by

        It depends where you hold your pki files, but i prefer certificate more than shared secret

        1 Reply Last reply Reply Quote 0
        • perikoP
          periko
          last edited by

          Thanks Metu69salemi for your input.

          What about the client key's  do we still need to use easy-rsa  ???

          Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
          www.bajaopensolutions.com
          https://www.facebook.com/BajaOpenSolutions
          Quieres aprender PfSense, visita mi canal de youtube:
          https://www.youtube.com/c/PedroMorenoBOS

          1 Reply Last reply Reply Quote 0
          • M
            Metu69salemi
            last edited by

            you could try out in build certmanager

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.