Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Tutorial: Configuring pfSense as VPN client to Private Internet Access

    OpenVPN
    99
    348
    418.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      I guess I don't know.  You've got something wrong somewhere.  Delete it all and start over maybe.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • B
        bj24
        last edited by

        :)

        1 Reply Last reply Reply Quote 0
        • B
          bj24
          last edited by

          Will start fresh and see how it goes… cross your fingers  ;)

          1 Reply Last reply Reply Quote 0
          • B
            bj24
            last edited by

            HOLD UP.  My last post I noticed my IP address in the lower right corner and it wasn't mine, it was the IP of the VPN!! So something is working.

            I go to speedtest.net and it shows my current location and ISP IP.
            I go to whatismyip.org and it shows my ISP IP and location.

            What is going on? Why did my post or this forum recognize the VPN but nothing else seemingly?

            steps forward…

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              There is nothing in your config that cares about the destination unless you're not telling us everything.  Is your VPN going up and down?  Lots of sites report IP addresses.  What does www.ipecho.net say?  What does www.wimi.com say?

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • B
                bj24
                last edited by

                Derelict,

                What do you imply that I wouldn't be telling?

                Every time I check the status of the VPN it is up and well. When I use the PC application the VPN is very stable. The logs for openVPN don't show anything strange.

                Both of those site showed my ISP IP.

                Any other logs I should be looking at?

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  Status > OpenVPN has a connected since column.

                  I say there's something else afoot because if there wasn't it would be working.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • B
                    bj24
                    last edited by

                    I checked the connection time and it was up for almost a day now.

                    I tried unchecking the "Don't add/remove routes" box. To my amazement when I checked the IP it was my VPN! How ever when I checked it on a PC that should be on the ISP is was showing the VPN. I changed it back.

                    I tried checking "Don't pull routes" too but that didn't seem to help.

                    1 Reply Last reply Reply Quote 0
                    • B
                      bj24
                      last edited by

                      If I use the website ipleak.net I get these results…

                      Showing my ISP IP 50.*** and also my VPN IP 104.***

                      what gives?

                      Capture.JPG_thumb
                      Capture.JPG

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        Are you running squid?

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • B
                          bj24
                          last edited by

                          I do have squid

                          1 Reply Last reply Reply Quote 0
                          • DerelictD
                            Derelict LAYER 8 Netgate
                            last edited by

                            @bj24:

                            I do have squid

                            You're on your own then.  Unbelievable.

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            1 Reply Last reply Reply Quote 0
                            • B
                              bj24
                              last edited by

                              I turned off squid and it works as expected now.  :o ::) :-[

                              I had no idea squid would be interfering especially if I am going to uncached never before visited sites like the ones you suggested to try.

                              Thank you for the suggestion!

                              So no squid + VPN setup? Or will more configuring will be required if I want both?

                              Thanks again, I can live without squid I think.

                              1 Reply Last reply Reply Quote 0
                              • DerelictD
                                Derelict LAYER 8 Netgate
                                last edited by

                                Thanks again, I can live without squid I think.

                                Most people don't need it.  it just breaks things.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • B
                                  bj24
                                  last edited by

                                  proven  ;D

                                  thanks again!

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    stanthewizard
                                    last edited by

                                    Thanks It works for specific IP (static) in the LAN

                                    Is there a way to route the traffic based on IP or URL ? (for netflix for exemple)

                                    Thanks

                                    1 Reply Last reply Reply Quote 0
                                    • B
                                      bj24
                                      last edited by

                                      It is very similar to routing static IPs.

                                      Under Firewall rules : LAN you'll want to make a rule for:

                                      Source: being your static IPs being routed, or leave blank if all

                                      Destination: being the IP address of the website you are trying to route

                                      Gateway: being the VPN or default as need requires

                                      1 Reply Last reply Reply Quote 0
                                      • S
                                        stanthewizard
                                        last edited by

                                        Thanks

                                        I already have some IP that are routed to openvpn

                                        I wanted to know if all IP coudl be routed based only on url ?

                                        :D

                                        1 Reply Last reply Reply Quote 0
                                        • B
                                          bj24
                                          last edited by

                                          Source: *

                                          Destination: being the IP address of the website you are trying to route

                                          Gateway: being the VPN

                                          1 Reply Last reply Reply Quote 0
                                          • DerelictD
                                            Derelict LAYER 8 Netgate
                                            last edited by

                                            The trouble is a "website" will load assets from many different domains.  Run NoScript for a while.  And that'll just show you all the different places the site is trying to pull javascript from.  Not images, etc.

                                            You can make aliases that periodically look up FQDNs and put all the IP addresses in a table.

                                            Chattanooga, Tennessee, USA
                                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.