Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN fails after LAN IP address change

    Scheduled Pinned Locked Moved OpenVPN
    10 Posts 4 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • KOMK
      KOM
      last edited by

      Running pfSense 2.1.

      I had my test unit working perfectly with OpenVPN.  Then I changed the LAN IP address.  Now my OpenVPN clients can connect but can't get anywhere in the network.  I even tried disabling all firewall Block rules.

      Is this a cert authentication issue due to the IP change???

      1 Reply Last reply Reply Quote 0
      • P
        phil.davis
        last edited by

        The OpenVPN server settings screen has a field to put "Local Network/s" - the old LAN subnet is probably in there, update it.

        Thought: It would be nice if these fields allowed use of "LAN net" or an alias that contained a network/s. Then it can automatically generate itself when the LAN interface address or the alias is changed.

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • KOMK
          KOM
          last edited by

          That's not it.  Went from 10.10.0.x/16 to 10.10.4.x/16, so nothing should change.

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            Since I had done all of this virtually and had the foresight (for once) to take a snapshot before making my changes, I simply rolled back to my snapshot and carried on.

            The moral of the story, for me anyway, is to make damned sure what your IP addresses are going to be before you install because changing them may break stuff.

            1 Reply Last reply Reply Quote 0
            • C
              costasppc
              last edited by

              Hi,

              Did you check the OpenVPN firewall rules after you did the change?

              Best regards

              Kostas

              1 Reply Last reply Reply Quote 0
              • KOMK
                KOM
                last edited by

                I disabled them to make sure they weren't blocking anything.

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  Are you outbound nats auto or manual - if manual you would have to update them.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • KOMK
                    KOM
                    last edited by

                    Outbound NAT was set to Auto.

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      did  you restart openvpn after making the change?

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • KOMK
                        KOM
                        last edited by

                        Yes.  Anyway, don't worry about it.  I moved back to the old IP a few days ago, it's working fine ever since and I've moved on to other projects.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.