• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Multiple OpenVPN instances for dynamic ips

Scheduled Pinned Locked Moved OpenVPN
4 Posts 2 Posters 773 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    sibyl
    last edited by Dec 8, 2014, 9:00 PM

    Hello,

    I would like to know if it is possible to use different OpenVPN instances but restrict one individual user/pass for each instance.

    Each client uses dynamic ips, possibly in the same range.

    Thank you!

    Regards

    1 Reply Last reply Reply Quote 0
    • P
      phil.davis
      last edited by Dec 9, 2014, 1:57 AM

      You can setup many OpenVPN "road warrior" servers, each listening on a different port and having a different tunnel subnet and different certificates.
      Then if you give the port number and authentication information for each server to just 1 user it will do what you are saying.
      Effectively each user will get the same internal IP address because each time they connect, they will be the only connection on that server.

      Is that what you meant?

      And what are you trying to achieve?

      As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
      If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

      1 Reply Last reply Reply Quote 0
      • S
        sibyl
        last edited by Dec 9, 2014, 5:12 AM Dec 9, 2014, 5:08 AM

        I would like to use a first instance of OpenVPN to access all services availaible at my office for employees only.

        Then I would like a second instance of OpenVPN restricted for only one person who wish to access only one service hosted at my office which will be also used by the first instance of OpenVPN.

        That makes sense?

        Thank you for the quick reply, really appreciate it!

        Btw, I know this can be done by using the server mode : peer to peer (shared key) but I was wondering if we could combine both the shared key with an authentification process.

        1 Reply Last reply Reply Quote 0
        • S
          sibyl
          last edited by Dec 9, 2014, 3:11 PM

          This did it for me :

          Marked this in the OpenVPN conf :

          Strict User /CN Matching : When authenticating users, enforce a match between common name of the client certificate and the username given at login.

          1 Reply Last reply Reply Quote 0
          1 out of 4
          • First post
            1/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received