OPNsense Forum

English Forums => 25.7 Series => Topic started by: dracocephalum on July 26, 2025, 06:33:28 AM

Title: [25.7] Legacy OpenVPN clent to new OpenVPN transition
Post by: dracocephalum on July 26, 2025, 06:33:28 AM
Hi team, since the legacy OpenVPN module is being retired, I am in the process to convert my 2 OpenVPN clients to the new OpenVPN client "instances".

However, it seems the new OpenVPN client "instances" are not feature-comptible with the legacy OpenVPN.

The issues I have encountered so far:
1. It seems we cannot specify an "interface" for the VPN connection (I specified "WAN" as the interface for my legacy OpenVPN connection)
2. There is no "Don't add/remove routes" option - I believe this is the default behavior for the new OpenVPN client?
3. The "Compression" dropdown box is gone, and this is where I got stuck - I need to set it to "Partial" (e.g. --compress) for the connection to my VPN provider to work
4. I was also setting extra options like: `remote-cert-tls server`, `fast-io`, `sndbuf 524288`, `rcvbuf 524288` etc. but doesn't seem like the new OpenVPN module allows me to do that

Any ideas how I can get the new OpenVPN clients up and running?

Thanks!
Title: Re: [25.7] Legacy OpenVPN clent to new OpenVPN transition
Post by: tessus on July 27, 2025, 12:18:53 AM
I asked similar questions (https://forum.opnsense.org/index.php?topic=46723.msg234324#msg234324) in the VPN sub-forum. I never got a reply. But what I can see is that several options are missing and it's not possible to set them. Maybe there is a way in a config file, but I haven't found that yet.

But to answer point 2 of your list: under Miscellaneous -> Options -> set route-noexec