• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Port for almost certain OpenVPN access?

Scheduled Pinned Locked Moved OpenVPN
3 Posts 3 Posters 966 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    tomstephens89
    last edited by Apr 7, 2016, 10:04 AM

    Hi guys,

    I have been using OpenVPN on pfSense as my 'out on the road' VPN solution for nearly 3 years now. However I have had a couple of issues when I am connected to some more restrictive public wifi hotspots. They obviously do not allow UDP 1194.

    Im thinking that changing the VPN server to UDP 53 which is DNS, so therefore more likely to be allowed outbound from most networks that 1194 right?

    Does anyone see any issues with this or have a better solution that I don't know about?

    1 Reply Last reply Reply Quote 0
    • D
      Derelict LAYER 8 Netgate
      last edited by Apr 7, 2016, 10:35 AM

      You can try it but it'll ultimately be an "it depends" situation.

      There is little if any reason to block outbound UDP/1194 in a public hotspot setting, other than to inconvenience your guests.

      The same admin that thinks it's a good idea to block that sort of traffic might very well block UDP/53 to anything but the local or preferred DNS resolver given out by DHCP.

      The best thing to do is probably complain or take your money elsewhere.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • J
        johnpoz LAYER 8 Global Moderator
        last edited by Apr 7, 2016, 11:08 AM

        I run udp 1194 and tcp 443..  443 is going to be open if they allow internet access ;)  While it also allows you to bounce the vpn connection off a proxy if they are doing that too.

        It might not be the place blocks udp 1194 on purpose, they might just be allowing the known ports for typical internet access.  So maybe they only allow dns, http/https, etc..

        Try your udp connection, if doesn't work then just fall back to tcp over 443.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        2 out of 3
        • First post
          2/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received