Tutorial: pfsense OpenVPN Configuration For Remote Users 2020

แชร์
ฝัง
  • เผยแพร่เมื่อ 23 ม.ค. 2025

ความคิดเห็น • 209

  • @LAWRENCESYSTEMS
    @LAWRENCESYSTEMS  4 ปีที่แล้ว +61

    At the 3:30 mark I meant to say "Leave it at the UDP default, not the TCP Default.

    • @James_Knott
      @James_Knott 4 ปีที่แล้ว +1

      I was going to mention that, but then saw your comment. The reason for UDP is TCP flow control. If you use TCP for the tunnel, then the 2 levels of flow control can interfere, causing poorer performance. On the other hand, TCP might be necessary to escape from a network that blocks everything but browsers, as my local library does.

    • @bertblankenstein3738
      @bertblankenstein3738 2 ปีที่แล้ว

      Thank you. I decided to remove the server, and remove the firewall rule. Then reran the wizard and had it add the FW rules back in.

  • @elesjuan
    @elesjuan 4 ปีที่แล้ว +9

    How the heck am I constantly watching your videos, but not subscribed? You've helped me so much with PFSense setup. Thanks dude!!

  • @santerisiiranen3924
    @santerisiiranen3924 4 ปีที่แล้ว +13

    About the TCP vs UDP questions: there is no need to use TCP here since all connections your vpn clients make will assume that the network is "unreliable" and therefore themselves use TCP to guarantee packet delivery. Using TCP to carry OpenVPN just adds unnecessary overhead to the connection. For this reason - always use UDP for OpenVPN by default.
    (Use case for TCP could be for example to host OpenVPN at port 443/TCP (https port) which may bypass some restictive firewalls etc)

  • @shaunnichols4664
    @shaunnichols4664 4 ปีที่แล้ว +20

    I'm glad you had certs already configured. I don't. I skipped over it even though its probably important.

  • @JustinShaedo
    @JustinShaedo 2 ปีที่แล้ว +2

    Working Notes for self:
    0:30 description of setup/goals
    1:55 PFSense Wizard
    VPN -> OpenVPN
    (* install openvpn-client-export from System>PackageManager>AvailablePackages)
    OpenVPN Rmove Access Server Setup
    Tunnel Network: ensure doesn't conflict
    Local Network: ?? should be list of LAN networks?
    Duplicate Connections: May be useful for rapid disconnect/reconnect scenario
    [NEXT] 9:20
    tick firewall and openvpn rules
    [NEXT] 9:32
    [FINISH]
    under Actions, click 'pen' to fine tune
    - Certificate Depth: 10:11
    10:52 Client Export
    Remote Access Server (essentially list of VPNs created)
    18:53 Trouble Shooting
    *read error messages*
    Status>System Logs>OpenVPN
    *BackUp*
    Diagnostics>Backup & Restore
    - See connected users:
    VPN>OpenVPN>{top right bar-graph icon}
    AND/OR
    Dashboard>[+]>OpenVPN

  • @pichonPoP
    @pichonPoP 4 ปีที่แล้ว +4

    I don't know why, but 10:57 apparently openvpn client export does not want to work on my side.

    • @SalamanderDancer
      @SalamanderDancer 4 ปีที่แล้ว +4

      If there aren't any users listed in the OpenVPN Clients portion of the Client Export Utility page, try System > User Manager, create a user and create a user certificate for them.

    • @Ck87JF
      @Ck87JF 4 ปีที่แล้ว +3

      @@SalamanderDancer Yeah, seems Lawrence skipped that part. I was confused too, but found this link to be helpful:
      docs.netgate.com/pfsense/en/latest/book/openvpn/configuring-users.html#openvpn-users-createlocal

    • @wannabetechie1494
      @wannabetechie1494 4 ปีที่แล้ว +1

      @@Ck87JF Excellent, Thank you for this. I was like damn i missed something

    • @Ck87JF
      @Ck87JF 4 ปีที่แล้ว

      @@wannabetechie1494 you're welcome. I'm still stuck actually haha. Even doing everything from the video and the link I posted, the VPN is running but I can't connect to it. Gonna delete everything and start over again.

    • @wannabetechie1494
      @wannabetechie1494 4 ปีที่แล้ว +1

      @@Ck87JF yeah, I am stuck too. I am stuck at unable to contact daemon...I feel there is a step missing for public IP address. I have setup OpneVPN on my server and had to use duckdns for a domain.

  • @mannyvelez7571
    @mannyvelez7571 ปีที่แล้ว

    Thank you! Finally got it working thanks to your video! Amazing work as always. Thank you very much for your time and help!

  • @_dvarapala
    @_dvarapala 2 ปีที่แล้ว

    @10:58 When you do the client export you have two users "admin" and "tom" - where did those come from? I'm following the tutorial step by step and I see no users at all at this step.

    • @nmedanee
      @nmedanee 2 ปีที่แล้ว

      System > User Manager > Users - Here you create a new user (or edit an existing what you want ot use for VPN authentication) and be sure that at the User Certificates tab you select the cert you created for the VPN.

  • @StefaninThailand
    @StefaninThailand 3 ปีที่แล้ว +1

    Thank you Tom i found the problem, was good to look at the firewall logs as well, private networks was blocked on wan side

  • @MrJchuayap
    @MrJchuayap 3 ปีที่แล้ว +1

    Hi is it possible to do a Site to site VPN using PFsense and Openvpn combined with remote users (also conneting thru open VPN via remote) being able to access both sites of the site to site VPN network?

  • @davidphilipleeful
    @davidphilipleeful 2 ปีที่แล้ว

    excellent. the pfsense documentation is scary. this makes it look easy

  • @amir36246
    @amir36246 3 ปีที่แล้ว +1

    HI, I m glad full for your work, it really helps a lot but I think the whole Clients part is missing!

  • @random_tech_stuff
    @random_tech_stuff 4 ปีที่แล้ว +3

    Thank you, very informative! If I may suggest, though, lowering your screen resolution would help tremendously viewers read text. Often times I watch TH-cam vids on my smartphone, but with yours, I have to sit in front of my PC or TV. Have a nice day!

    • @jameswhite8697
      @jameswhite8697 3 ปีที่แล้ว

      Your point is great for people who are using their phone - but I, for one, am using my full screen and these videos are perfectly formatted for me.

  • @emanuelelauretta2265
    @emanuelelauretta2265 4 ปีที่แล้ว

    Thank you for the video, but mostly thank you for the Italian flag behind you ( green+white+red) ! AWESOME!

  • @loganhawkins6486
    @loganhawkins6486 ปีที่แล้ว

    Thank you for the view this has been a lot of help, however I am not seeing any downloads, do I need to create users/clients and how do I do that

  • @DaveLucre
    @DaveLucre 4 ปีที่แล้ว +5

    Can you please explain your choice of TCP over UDP?

    •  4 ปีที่แล้ว

      Brandy.

  • @zoltanhorvath1156
    @zoltanhorvath1156 4 ปีที่แล้ว +33

    I is a bit confusing. You did not show how how to configure the clients.

    • @darasithin7906
      @darasithin7906 3 ปีที่แล้ว +3

      yeah, I still wondering what is the client configuration anyway, but as you can see in the video. There's no need client configuration required for the connection. only the server is configured and users is created in user manager with same cert as the server then we can get the certified connection.

  • @JadeDevon
    @JadeDevon 4 ปีที่แล้ว +1

    Your fingers do not like .40 - they most definitely default to .30
    Thanks for the updated video Tom

  • @ramrod2k
    @ramrod2k 2 ปีที่แล้ว

    Where can i find the video on "Custom options" as mentioned at 22:08 ?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 ปีที่แล้ว +1

      Custom options is simply a way to pass any special parameters through to OpenVPN that are not in the pfsense web UI.

  • @michaeljaques77
    @michaeljaques77 4 ปีที่แล้ว +6

    Tom, I'm a little confused on the certificate part of the setup. Are you still using a LE signed certificate, or an internal certificate? Maybe I missed something in the instructions.
    I know you have to go into "User Manager" and add a certificate then assign it in the OpenVPN server configuration , but did you make a specific LE certificate just for VPN?

    • @joeroback4726
      @joeroback4726 4 ปีที่แล้ว +20

      yea it appears there is an entire "OpenVPN client" part missing from this video...

  • @fbifido2
    @fbifido2 4 ปีที่แล้ว +2

    @6:31 - can you force just a few apps to route all traffic via the VPN?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 ปีที่แล้ว +1

      That is called split tunneling th-cam.com/video/XHtwVJt4AKo/w-d-xo.html

    • @fbifido2
      @fbifido2 4 ปีที่แล้ว +1

      @@LAWRENCESYSTEMS So, i have to know the ip or DNS the app is looking for, then push that onto the openVPN custom route?
      say I want IE to use the VPN for everything and Google Chrome & Microsoft Edge to not use the VPN?

    • @rayjaymor8754
      @rayjaymor8754 4 ปีที่แล้ว

      @@fbifido2 Can't do that one no. Closest you can do is direct IE to use a Proxy server and have the Proxy server go over the VPN. Note that this would direct your traffic for that browser but will do very little from providing anonymity perspective.

    • @toneldaclan9283
      @toneldaclan9283 4 ปีที่แล้ว

      @@LAWRENCESYSTEMS How do I setup my OpenVPN in pfSense (internal firewall) behind another pfsense router (facing public)

  • @DaFakaMatt
    @DaFakaMatt 3 ปีที่แล้ว

    Lots of people don't read the logs or error messages. So true.

  • @throttlebottle5906
    @throttlebottle5906 4 ปีที่แล้ว +1

    tunneling ipv6 over it isn't bad on it, providing you have at least one free static /64 block or more if you want multiple ovpn servers, each will need a /64 block.
    I just picked whatever random /64 out of the he net/48 tunnel. of course making sure it doesn't overlap it with other lan/opt which have prefix delegations enabled for sub-routers

  • @scottpeal60
    @scottpeal60 3 ปีที่แล้ว +1

    Worked great. Would help to show how to add a user though.

  • @lynskyrd
    @lynskyrd ปีที่แล้ว

    Nice video I got everything working so I decided to find out what would happen if I rekeyed a user cert with the option to regenerate a new key. I discovered that the user could still connect to OpenVPN with the old config file. ???? I assumed a a rekey would mean I would have to send this user a new config but I'm now curious- other than removing the user entirely or reassigning a password- how do you make their 'old' config invalid? thanks again for making this tutorial- well done.

  • @HomeBudgetComputing
    @HomeBudgetComputing 3 ปีที่แล้ว +2

    If you have a dual WAN setup with failover (as shown in another of your great videos), do you need to make a VPN for each WAN connection? Perhaps name the one on the failover "Backup VPN" so your users can access the VPN if the main internet connection is down?
    Thanks for taking the time to make these videos.

    • @IndyColts1987
      @IndyColts1987 ปีที่แล้ว

      you can go into the windows client settings and find the file path for the config. Just copy it and edit the public IP to your backup. Then you have one profile for each.

  • @per-mortenevensen941
    @per-mortenevensen941 3 ปีที่แล้ว

    What about the warning server auth-nocache, how to fix. I just installed this in my windows laptop and saw this warning.

  • @BorisJohnsonMayor
    @BorisJohnsonMayor 3 ปีที่แล้ว

    Did I space out or was there no explanation on how he signs into the VPN with auth credentials? Where do you create those accounts?

  • @amielcarlohuet2496
    @amielcarlohuet2496 3 ปีที่แล้ว

    Hi, When the "Redirect Gateway" is not check, client does not have internet connection, Could you please tell me why? thanks.

  • @jimmatrix7244
    @jimmatrix7244 3 ปีที่แล้ว

    Having problem connecting to pfsense's openvpn from host machine. VM Wan interface is bridged but cannot ping from host although in same subnet. Any workaround? Thanks.

  • @rodgersmomanyi2756
    @rodgersmomanyi2756 2 ปีที่แล้ว

    Hi Tom, been having a problem pinging a server that is assigned a static IP on the lan side. When connected on open VPN I can ping any lan side ips assigned via dhcp but cannot ping those assigned statically on the lan side

  • @Dfk429S9fo3
    @Dfk429S9fo3 4 ปีที่แล้ว +1

    Is it possible to get OpenVPN to autoconnect at Win10 startup before loggging in, so that it will log in to the domain and get all the drive maps? Everything I've seen that is supposed to accomplish this hasn't worked. :(

    • @MrDrpt
      @MrDrpt 4 ปีที่แล้ว

      You can run OpenVPN as a service.

  • @paulvancyber1979
    @paulvancyber1979 4 ปีที่แล้ว

    thanks!!!! really really good content!!! greetings from mexico!!!!! im will start to use pfsense with all my clients! and this is cause u make a superb tutorials!

  • @oldlock74
    @oldlock74 4 ปีที่แล้ว

    I found your guide useful for adding remote access (windows) what I am having trouble pinning down is a step by step guide for adding site to site tunnels where the remote end is not pfsense (ie uses ipsec etc). There is a fair bit of info but nothing from beginning to end that I can see ?

  • @MakoaSantarini
    @MakoaSantarini 2 ปีที่แล้ว

    Your videos are so good. Thank you

  • @YeOldeTraveller
    @YeOldeTraveller 4 ปีที่แล้ว

    I assume you could create a VPN with all traffic, and another that is the same except that it does not route all traffic.

  • @Egimatic
    @Egimatic 4 ปีที่แล้ว

    Do u have a video where u show how u installed pfsense for this network?

  • @philippe_demartin
    @philippe_demartin 4 ปีที่แล้ว

    Nice episode, but I have a problem.
    I've got a client who is connected to a ISP who don't gave him a public ip adress.
    This local ISP is running a sort of nat to the client, who's adresse is 192.168.35.220 !!!
    So now, to get to this opensense firawall, I wrote a script to establish a reverse ssh to a DigitalOcean instance to forward the 80 and 22 ports, but is less than ideal.
    Can you make a tutorial for a better solution: IpSec, or something else.
    It would be greate to have ZeroTier working on Pfsense, but until now, I was unable to get it working.

  • @jamesa4958
    @jamesa4958 2 ปีที่แล้ว

    Thank you, referred back to this many times.

  • @turriturri123
    @turriturri123 11 หลายเดือนก่อน

    If you are going to create a tutorial for configuration perhaps next time also include the certification/user creations as well

  • @jonathanzj620
    @jonathanzj620 ปีที่แล้ว

    What happened to the client piece? Those don't just auto-populate.

  • @Rambin123
    @Rambin123 3 ปีที่แล้ว

    Does this work if your ISP has a nat behind your home router?

  • @minigpracing3068
    @minigpracing3068 4 ปีที่แล้ว

    Just an FYI, I figured out the problems I was having with my site to site with key link. If you use 172.XXX.0.0/16 for the tunnel network, the gateways won't come up. If you subnet that down to /24 the gateways will (probably) come up. Mine popped to life as soon as I made the change on both ends. I didn't see that limitation in the manual, and probably no one has ever tried being that sloppy with the tunnel network.

  • @it-everything
    @it-everything 4 ปีที่แล้ว

    Thank you so much very well explained, However it is not showing the OpenVPN Clients even i can't see the user and certificate name and they are created and exist? Thanking you in advance for any help if you can.

  • @rayx9981
    @rayx9981 2 ปีที่แล้ว

    I have tried to use lan IP but it is not working. However, I switch to my isp IP it works. why ?

  • @strait6
    @strait6 4 ปีที่แล้ว

    What to do when I got double-nat.....basically the WAN of pfSense is in the DMZ of my router, which then has public IP. Because in the server config the IP clients would connect to is an internal IP. Should I just change that to the public IP

    • @strait6
      @strait6 4 ปีที่แล้ว

      Solved...just changed the IP in the profile file to my real public IP and it works like a charm

  • @yarbinmalawi8288
    @yarbinmalawi8288 2 ปีที่แล้ว

    I have no clients - did this go over the client setup? My client export is empty.

    • @nashonabo821
      @nashonabo821 2 ปีที่แล้ว

      For anyone else who hadnt figured it out, go to User Manager, click the username you created (or create a new one) under user certificates, click add. Ensure the proper CA is selected (The one you used for your OpenVPN server) and add a common name. You should then see the certificates located under your user certificates. Go back to Client export and it should show.

  • @pcricardoSouza
    @pcricardoSouza 4 ปีที่แล้ว +1

    Você podia criar um livro sobre a configuração do PFsense, muito show!

  • @andreasdamen
    @andreasdamen 4 ปีที่แล้ว

    I have a question. Because the firewall I want to connect to with OpenVPN is behind another firewall (assignment for school). The connection worked before I created the second firewall but now i can't connect anymore. Do you maybe know the cause of this?

  • @nacbk1
    @nacbk1 4 ปีที่แล้ว

    On a client machine, like a laptop, how do you load multiple OpenVPN clients. Example, you are a tech that supports many clients and you need to access their systems ( not at the same time of course). How do you load the clients?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 ปีที่แล้ว +1

      Just copy all the config files into that same folder.

    • @Dfk429S9fo3
      @Dfk429S9fo3 4 ปีที่แล้ว +1

      One client, just have to select which config to connect with.

  • @eric5121
    @eric5121 4 ปีที่แล้ว

    Is there a way to monitor the bandwidth going through OpenVPN? I tried to see it in Ntopng, but the addresses don't show up.

  • @Miltos95
    @Miltos95 4 ปีที่แล้ว +1

    Isn't TCP over TCP going to be a mess? Shouldn't we let the application handle the packet loss like it would without the VPN?
    How do realtime applications behave via TCP VPN?

  • @chpalmer2007
    @chpalmer2007 2 ปีที่แล้ว

    Is "redirect-gateway def1" on the remote config still required if redirecting all traffic?

  • @aguinaldopedro3346
    @aguinaldopedro3346 2 ปีที่แล้ว

    Hi Lawrence thank you so much for your videos, I have seen your videos to strengthen my pfsense knowledge, during vpn configs, it raised a question what should be the best option to opt for between udp vs tcp?

  • @nowdays1824
    @nowdays1824 4 ปีที่แล้ว

    My internet provider puts me behind their nat (CGNAT) so it will work in that condition? pls make a video there is so much confusion there is no perfect form out there

  • @adakaitalker3273
    @adakaitalker3273 3 ปีที่แล้ว

    Is it possible to do this with a double NAT? If so, could you direct me to a guide or information regarding this? Thank you.

  • @mymusicchannel5625
    @mymusicchannel5625 4 ปีที่แล้ว

    Hi, can we run VPN server on shared internet it have dynamic IP's for accessibility from Home to Office .

  • @yongshixian9779
    @yongshixian9779 2 ปีที่แล้ว

    HI, on the 17.54, the username and password comes from where?

  • @AL3X36000
    @AL3X36000 3 ปีที่แล้ว

    Hi, great video, however i face issues such as disconnecting using openVPN on my pfsense : i read that came from keepalive but, i don't how to configure this... Do you have any idea?

  • @mattiaippolito1625
    @mattiaippolito1625 4 ปีที่แล้ว

    Hello: Two questions. 1st what if I want to connect two different office as they act as just one big LAN network? 2nd can I create a VPN Tunnel between two pfsense Firewall on two office without the need to run the client on each computer?

    • @descod5863
      @descod5863 4 ปีที่แล้ว

      yes - GRE

    • @mattiaippolito1625
      @mattiaippolito1625 4 ปีที่แล้ว

      Des Cod how?

    • @descod5863
      @descod5863 4 ปีที่แล้ว

      @@mattiaippolito1625 th-cam.com/video/nXGc5dw_FlI/w-d-xo.html (rus)

    • @descod5863
      @descod5863 4 ปีที่แล้ว

      @@mattiaippolito1625 you can screw GRE + IPSec

    • @mattiaippolito1625
      @mattiaippolito1625 4 ปีที่แล้ว

      Des Cod I don’t speak Russian

  • @gglovato
    @gglovato 4 ปีที่แล้ว

    You mention you did a video on authentication backend, i honestly can't find it on the pfsense playlist(i don't see it on the basic pfsense install video for example)

  • @intellectualgravy9796
    @intellectualgravy9796 4 ปีที่แล้ว

    As always SUPER INFORMATIVE. GOOD JOB TOM.

  • @bobsimon1554
    @bobsimon1554 ปีที่แล้ว

    thanks for the video.
    How do i specify a local group just to use this vpn..cannot find the option.

  • @usaevo8
    @usaevo8 2 ปีที่แล้ว

    Hey Tom, just reviewed this video and it needs a bit of help fixing inconsistency in the setup and you jumped back and forth a couple times. Any chance this one will get a refresh?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 ปีที่แล้ว

      Other than being older, what is inaccurate?

    • @IndigoVikingTV
      @IndigoVikingTV 2 ปีที่แล้ว

      @@LAWRENCESYSTEMS There is no client export option, in fact there are only 4 tabs now vs. the 6 in your video. So there is no information on how to set up a client

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 ปีที่แล้ว +1

      @@IndigoVikingTV If that is missing then you skipped the step in the video where I said to load the OpenVPN export package.

    • @IndigoVikingTV
      @IndigoVikingTV 2 ปีที่แล้ว

      @@LAWRENCESYSTEMS Ah you're right, that was it. I am new to pfsense as of Saturday and my brain is fried...it's been refusing my VPN connection and I've been down a long rabbit hole of videos trying to get this working to no avail.

  • @ryanstrom8866
    @ryanstrom8866 4 ปีที่แล้ว +1

    Hey I love your videos, thank you for all you do!

  • @cods41
    @cods41 4 ปีที่แล้ว

    Have you ever explained how you configure your “pseudo internet” network? I’d like to use something similar in my home lab.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 ปีที่แล้ว +1

      th-cam.com/video/o1nwUfHsDHs/w-d-xo.html

  • @umar7565
    @umar7565 3 ปีที่แล้ว

    Hi lawrence, thanks for great video. Issue - My connection establish locallay nut when i try connect on any other network or mobile hotspot it fails with error (TCP: connect to [AF_INET]x.x.x.x:1194 failed: Unknown error). please suggest. thanks

  • @jaywarren3505
    @jaywarren3505 4 ปีที่แล้ว

    if i don't do anything in regards to remote connectivity/administration, is setting up openvpn beneficial for me? i don't realy understand vpn's.

    • @mrlithium69
      @mrlithium69 4 ปีที่แล้ว

      When you're on your phone, or somewhere else, This would allow you to securely connect back to your home router and access private NAS resources or other home computers instead of exposing them directly to the internet.

  • @mattiaippolito1625
    @mattiaippolito1625 4 ปีที่แล้ว

    Everything works as described as long as I'm connected via the same wifi network, if I try to connect over LTE I am not able to successfully connect to openvpn server..... any help?

  • @epitomeofsalt1648
    @epitomeofsalt1648 4 ปีที่แล้ว

    Im unsure if ill get a reply but I was able to get it connected. Theres a route made for the internal network but I cant ping anything. I can ping the pfsense interface(192.168.5.1) but am not able to ping the clients ip in the network(192.168.5.10). Any suggestions?

  • @Kolan_Koala
    @Kolan_Koala 4 ปีที่แล้ว +1

    Hi Tom, what are your thoughts on correct open VPN settings for OpenVPN Client using PIA servers with regards to mssfix, link-mtu and tun-mtu in order to prevent IP fragmentation?
    (WAN is PPPoE with MTU of 1492). Do these need to be set manually or just let OpenVPN figure it out? This is pfSense 2.5.0 dev version. Thanks from Australia. 🦘

  • @biggyk87
    @biggyk87 4 ปีที่แล้ว

    So sorry is this LAN traffic only or does all Internet traffic get routed?

  • @rumar4u
    @rumar4u 4 ปีที่แล้ว +1

    Can you show your firewall rules in PFSense ?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 ปีที่แล้ว +1

      They are the default once from the wizzard

  • @johnharrison712
    @johnharrison712 2 ปีที่แล้ว

    I would like to use PFsense with OpenVPN but I want to also have Certificates in places to be able to connect. Is this possible?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 ปีที่แล้ว +1

      Yes

    • @johnharrison712
      @johnharrison712 2 ปีที่แล้ว

      @@LAWRENCESYSTEMS is there a video you recommend that show me how to do it. I selected the option but it doesn’t persistent

  • @attilavidacs24
    @attilavidacs24 4 ปีที่แล้ว +2

    Please help I'm getting:
    TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
    TLS Error: TLS handshake failed

    • @maskedviperus
      @maskedviperus 4 ปีที่แล้ว

      In a lab setting you gotta uncheck these settings on wan. I scratched my head for 3 days til i realized its not gonna let internal ip's into wan
      Block private networks and loopback addresses
      Blocks traffic from IP addresses that are reserved for private networks per RFC 1918 (10/8, 172.16/12, 192.168/16) and unique local addresses per RFC 4193 (fc00::/7) as well as loopback addresses (127/8). This option should generally be turned on, unless this network interface resides in such a private address space, too.
      Blocks traffic from reserved IP addresses (but not RFC 1918) or not yet assigned by IANA. Bogons are prefixes that should never appear in the Internet routing table, and so should not appear as the source address in any packets received.
      Note: The update frequency can be changed under System > Advanced, Firewall & NAT settings.

  • @JhonnattanMartinezH
    @JhonnattanMartinezH 4 ปีที่แล้ว

    Tom, first thank you for your videos.
    I have the following issue: every time the ISP changes the IP address I have to export a new config file and reinstall on the client's computers this is a no brainer if you only have one or two clients but in my case is like 15.
    can you do a followup with that scenario, please?
    Thanks you.

    • @SteveRockie
      @SteveRockie 4 ปีที่แล้ว +1

      You can look into NoIP DNS and use something similar

  • @williamshenk7940
    @williamshenk7940 3 ปีที่แล้ว

    NIce video, you made this cool feature easy to implement.

  • @michaelbenstead1235
    @michaelbenstead1235 4 ปีที่แล้ว +1

    Great video but you did not talk about adding users in pfsense ...simple but some may not know.

  • @nanaa9074
    @nanaa9074 4 ปีที่แล้ว

    OPTIONS ERROR: failed to negotiate cipher with server. Add the server's cipher ('AES-256-CBC') to --data-ciphers (currently 'AES-128-GCM') if you want to connect to this server.
    ERROR: Failed to apply push options
    Failed to open tun/tap interface
    How do I fix this in OpenVPN?

  • @kwabenasarpong3862
    @kwabenasarpong3862 4 ปีที่แล้ว

    can i get help on how to configure the openvpn on mobile phone for both android and ios?

  • @WOLFITTIPS
    @WOLFITTIPS 4 ปีที่แล้ว

    any idea why im getting TCP: connect to [AF_INET]192.168.100.111:1194 failed: Unknown error?

  • @kmcat
    @kmcat 4 ปีที่แล้ว +1

    Can you make a tutorial on L2TP with IPSec.

  • @JoeSmith-kn5wo
    @JoeSmith-kn5wo 4 ปีที่แล้ว

    Thanks. I learned a lot from this video.

  • @Radenska512
    @Radenska512 ปีที่แล้ว

    Is this safe to do? Will I expose my network to the internet too much with OpenVPN?

  • @ruthlessadmin
    @ruthlessadmin 2 หลายเดือนก่อน

    I came here because I was stuck on the last step -- there were no client configs available for export. This is because my default admin user does not come with a user certificate. You have to add one manually. However, it's best just to create a dedicated user & group with no permissions for your VPN, rather than using the admin account.

  • @mactech8167
    @mactech8167 4 ปีที่แล้ว

    Ok thats great, thanks but need to know just 1 thing i’ve been wanting to do: what do I have to do in your senario to access the windows 10 entire subnet 10.0.2.0/24 from the ovpn server end
    If you can explain that in a video that would be great as that would be very useful
    On a “remote access vpn server” as you have there not a site to site ovpn server

  • @jacobsamdal9611
    @jacobsamdal9611 4 ปีที่แล้ว +1

    Tom, Is there a way I can access my home NAS using this? Or maybe I am doing something wrong! Thanks man! I love your videos!!!

    • @john-r-edge
      @john-r-edge 4 ปีที่แล้ว

      Yes, for sure. I set up that capability; I followed Tom's earlier step by step TH-cam video for openvpn. Once I had done the setup I tested by connecting my laptop to the internet via the Android wifi hotspot which connects via mobile data.
      This setup used by me and another family member.

    • @tjmazur9697
      @tjmazur9697 4 ปีที่แล้ว

      Make sure Admin privilege enabled. When you set up, check box in OpenVPN, or per use. Otherwise, you can only get to the pfsense stuff. Been there & done that.

    • @jacobsamdal9611
      @jacobsamdal9611 4 ปีที่แล้ว

      @@john-r-edge I have followed both and it seems sometimes I can get it to connect and other times not. The very first time I tested it, I connected my hotspot to my laptop and it seemed to work. I have not been able to get it to connect since. I also can only sometimes get it to connect to the pfsense portal...

    • @jacobsamdal9611
      @jacobsamdal9611 4 ปีที่แล้ว

      @@tjmazur9697 I am not sure what youre saying. I dont see a checkbox to change it..Thanks

    • @tjmazur9697
      @tjmazur9697 4 ปีที่แล้ว

      @@jacobsamdal9611 Right click on desktop icon. Select Properties, select compatibility tab. The check box is here.

  • @hanchen7685
    @hanchen7685 3 ปีที่แล้ว

    HI..
    How to enable Web GUI remote access via OpenVPN?

  • @florensschneider7603
    @florensschneider7603 4 ปีที่แล้ว

    Thank you tom. Perfect tutorial. If i set the local network in the openvpn wizard to a vlan network. Is then the client automatically in the right vlan and has access? Is there any other step necessary? My plan is to create the vpn direct in the vlan.

  • @billsecond1
    @billsecond1 3 ปีที่แล้ว +1

    As usual, thanks!

  • @ddidci
    @ddidci 3 ปีที่แล้ว

    Very well presented information. Thank you.

  • @paulvancyber1979
    @paulvancyber1979 4 ปีที่แล้ว +4

    damn i dont have the openvpon clientes

  • @JuanLopez-db4cc
    @JuanLopez-db4cc 4 ปีที่แล้ว

    Does anyone know how to make it work using DynDNS or No-IP, cause my Public IP is Dynamic and not Static. I cant seem to make it work. What else needs to be done? Thanks!

    • @descod5863
      @descod5863 4 ปีที่แล้ว

      pfsens has a ddns setting. Either choose registered or ready
      .

  • @elabeddhahbi3301
    @elabeddhahbi3301 4 ปีที่แล้ว

    i can't find the video about openvpn with AD

  • @kanes5105
    @kanes5105 4 ปีที่แล้ว

    again, another great video!

  • @itdepartment9002
    @itdepartment9002 4 ปีที่แล้ว

    Hello sir,
    "Can't connect to OpenVPN (TCP: connect to [AF_INET]192.168.x.x:1194 failed: Unknown error..."
    I installed it to another laptop and get this error

  • @erickpalma4934
    @erickpalma4934 3 ปีที่แล้ว

    Could you make a version using LDAP? thanks love the videos!

  • @sebastianreal4363
    @sebastianreal4363 4 ปีที่แล้ว +1

    great video for this moment, thanks for sharing

  • @JeDeXxRioProKing
    @JeDeXxRioProKing 4 ปีที่แล้ว

    Thank you tom

  • @geepriest
    @geepriest 3 ปีที่แล้ว

    How do I log users that connect and disconnect?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  3 ปีที่แล้ว

      Pipe and parse the logs into a log processor