• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Multiple OpenVPN connections, routing based on country or rule set

Scheduled Pinned Locked Moved OpenVPN
5 Posts 3 Posters 3.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    phreshjive
    last edited by Apr 4, 2013, 12:06 AM Apr 3, 2013, 10:06 PM

    Hello,

    New to PfSense.  Longtime user of Tomato/DD-WRT.  Had a question for you experts out there that I am at a loss on how to solve.  I am using Private Internet Access.  I followed this guide: http://goo.gl/S3BsZ  to setup my OpenVPN connection.

    I would like the ability to set up multiple OpenVPN connections to servers in different countries.  For example, A would be US, B would Canada, and C would be UK.  I would then like to set up rules based on GeoIP to determine which connection should be used when I am online.  If the website or service is in country A, it should use VPN connection A, if in B, then use B and so on.  Default would be A. I would also like the ability to exclude either specific traffic/IPs from the VPN (for example my Cisco SPA2102 or Slingbox)

    Could someone kindly point me in the right direction or perhaps suggest a solution to accomplish same? I found the following information but couldn't translate it to pfSense so well: http://goo.gl/eGvVu  and http://goo.gl/BBUun

    Much appreciated.

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Apr 5, 2013, 12:22 PM

      You can use pfBlocker and its country lists to get aliases that correspond to IPs in various countries, and then use policy routing to direct traffic into the VPN you want based on those aliases.

      Both of those topics have been discussed many times on the forum – separately -- so you can likely find thorough instructions if you search for pfBlocker for the country part, and then a separate search for OpenVPN connecting to a service provider and using policy routing (look at the threads for things like StrongVPN).

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • P
        phreshjive
        last edited by Apr 9, 2013, 4:12 AM

        Thank you Jim for the reply.  I have tried over the last while to figure it out and unfortunately cannot.

        While I realize Jim is probably busy editing the new edition of the book, if someone else out there can handhold me a little more, it would be appreciated.

        1 Reply Last reply Reply Quote 0
        • C
          cmb
          last edited by Apr 10, 2013, 4:51 AM

          I see you posted a freelancers job to configure this and some additional items. We'd be glad to help with that via our commercial support. We can't ever commit to an exact price for a given job because the exact same job can vary a lot from one customer to another because our level of involvement varies. All the jobs along the lines of what you listed have been doable within our base 5 hour support subscription, though at times scope changes along the way. It's something we could have done within a business day if you purchase here.
          https://portal.pfsense.org/index.php/subscribe-for-access

          You can probably find cheaper alternatives, unknown people with unknown skills located who knows where. But trust me…save yourself some headaches and come to the world's foremost experts. We fix a lot of what random freelancers "implement", and have plenty of customers who wish they had just come to us in the first place rather than wasting their money and time with some freelancer.

          1 Reply Last reply Reply Quote 0
          • P
            phreshjive
            last edited by Apr 10, 2013, 3:32 PM Apr 10, 2013, 2:57 PM

            Chris,
            I want to thank you for all your hard work in furthering pfSense to what it is today.  What an extremely powerful and useful solution.
            For a home user like myself,  the support option is pricey to say the least.  My system to date has cost under $400 running an Atom based board and Ubiquiti Unifi AP Pro.  I'm positive someone with the requisite knowledge could solve my issues in a relatively short period of time.  Spending $600 though is out of my budget and the reason why I came to the forum.  I bought The Book of PF, pfSense 2 Cookbook, and your Definitive Guide and still was having difficulty solving my issues on my own.  
            My plan was to use either freelancer or elance to try and get someone to solve them then post up the solution here for whomever wanted the same setup.  
            I would wholeheartedly trust the world's foremost pfSense experts but unfortunately I just don't have the budget at present to support that option.

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received