Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN Server on pfSense with one interface in private subnet

    Scheduled Pinned Locked Moved OpenVPN
    6 Posts 4 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      ToMasz
      last edited by

      Hi all!

      Can I configure OpenVPN Server on platform with one interface (or virtual instance pfSense).
      The client must have access( from Internet) to the servers in a private network.

      OpenVPN Client
                                |
                                |
                          INTERNET
                                |
                                |
      ROUTER (Public IP, Server DHCP, NAT from Public IP TCP/1194 to OpenVpn server 192.168.1.200 TCP/1194)
                                |
                                |
                            SWITCH
                                |
            |___________
            |                |                  |            |        |
      Computer1  Computer2  Server1 …Server n OpenVPN Server
      192.168.1.1 192.168.1.2 192.168.1.3 .... n ---192.168.1.200

      I would be grateful for any help!

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        The problem with that is all your hosts on 192.168.1.0/24 having the router set as their default gateway and routing traffic for the OpenVPN clients to it instead of back to the OpenVPN server.  Routing traffic back out the same interface the traffic was received on is generally problematic and doesn't end well.  You get ICMP redirects and other general nastiness.

        Other than that I don't see why it wouldn't work.  I can't think of a reason OpenVPN would care that it's routing traffic out the same interface it's listening on (This is different from the above).  But I've never tried it.

        Is there another router interface on which you can put the OpenVPN server on its own subnet?

        Replace the router with pfSense?  ;)

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • T
          ToMasz
          last edited by

          I just want to pfSense realized only users authentication. Unfortunately, I can't replace main router. I don't have full access to it. The administrator can only redirect for me the ports on the private network.

          1 Reply Last reply Reply Quote 0
          • V
            viragomann
            last edited by

            Hi!

            I had such a set up running at time of replacement my old Firewall with pfSense to provide a nearly uninterrupted VPN service for the clients.

            pfSense with three OpenVPN severs was running on a VM. As I remember, it had two interfaces, however, both in the same subnet. Maybe it was not an optimal set up, but it worked well.

            1 Reply Last reply Reply Quote 0
            • B
              BoMbY
              last edited by

              I can't see we it shouldn't work. Had something like the OPs request running for a few minutes yesterday (before other problems occurred). I had it running as a tap (because I want to use LAGG), without actually bridging a physical ethernet adapter, and just routing/nat from the bridge IP to the public IP.

              1 Reply Last reply Reply Quote 0
              • T
                ToMasz
                last edited by

                I installed pfSense on VM with two interfaces WAN and LAN (Maybe I only need one interface -WAN?).
                TAP mode is optimal for me -because clients, connecting via vpn, must a have access to the network.
                I have not found a tutorial how to perform this configuration -please help!

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.