Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfSense in server only (one nic) as vpn client and router

    Scheduled Pinned Locked Moved OpenVPN
    2 Posts 2 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dyce
      last edited by

      Is it possible to have this setup

      Internet
          |
      Router
          |
        LAN
      |        |
      client  pfSense
                    |
                connected to vpn provider

      Can client use vpn provider if the static route is established to use the external openvpn servers gateway or do you have to install ovpn on the client?

      Also can pfsense run a ovpn server that can route clients to the vpn provider that the pfsense box is connected as a client to?

      I setup a vm with pfsense, used dhcp as wan. After adding the ovpn client connection I no longer can access the web configurator (is this because the LAN is added from the ovpn connection and now I have to open a port to the web configurator?)

      1 Reply Last reply Reply Quote 0
      • P
        phil.davis
        last edited by

        I setup a vm with pfsense, used dhcp as wan. After adding the ovpn client connection I no longer can access the web configurator (is this because the LAN is added from the ovpn connection and now I have to open a port to the web configurator?

        Before setting up the OpenVPN and assigning an interface to it, put the pass rules that you need onto WAN. The 2nd interface is "LAN" underneath, and when that appears, the anti-lockout rule goes there, rather than on WAN.

        You should be able to hard-code in the WAN-side client a default gateway (or route(s) if you just want it for some destinations) that points to pfSense WAN IP. Make sure pfSense WAN IP is a static mapped IP on "Router" so it does not change.
        Put appropriate pass rules on pfSense WAN to allow that traffic from client and policy-route it to the OpenVPN link-gateway.

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.