OPNsense Forum

Archive => 16.1 Legacy Series => Topic started by: teces on February 03, 2016, 09:44:38 am

Title: Unable to generate OpenVPN client install packages
Post by: teces on February 03, 2016, 09:44:38 am
Hello,

I'm trying to configure an OpenVPN Server with OPNsense and when I create clients I'm unable to get the client install packages.

I go to Client Export tab but no the client list to export is always empty.

What I'm doing wrong?

Thanks.
Title: Re: Unable to generate OpenVPN client install packages
Post by: franco on February 03, 2016, 10:15:28 am
Do you have users with assigned privileges for OpenVPN access and their certs assigned?
Title: Re: Unable to generate OpenVPN client install packages
Post by: teces on February 03, 2016, 11:34:46 am
Uff... I'm not sure how to do this...

I have createt an user under System->Access->Users
I have assigned this user Certificate created previously (with OpenVPN configuration wizard)

...what else? ...how do I assign privileges for OpenVPN?

Is there any guide or how-to configure an OpenVPN under OPNsense? ...I haven't found it and I'm recollecting information from PFsense and OpenVPN forums...

Thanks.
Title: Re: Unable to generate OpenVPN client install packages
Post by: brokenby2703 on February 08, 2016, 02:38:30 pm
Hi.

OpenVPN is giving me headache.

As per post of teces I'm not able to export .ovpn certificate.

In the VPN/OPENVPN/CLIENT EXPORT page there isn't any client list (see attachment).

I did follow this guide : https://www.kirkg.us/posts/building-an-openvpn-server-with-opnsense/

But Can't come out from there.

Anybody can help ?

Thanks

Title: Re: Unable to generate OpenVPN client install packages
Post by: AdSchellevis on February 08, 2016, 06:20:44 pm
Quick question, do your users have certificates assigned?
(Access -> Users -> "User Certificates")
Title: Re: Unable to generate OpenVPN client install packages
Post by: teces on February 10, 2016, 11:26:00 am
Hello,

I'm here again...

I have done this steps...

1. Create a Certify Authentication (under System->Trust->Authorities)

2. Create a Server Certificate using Certify Authentication created in step before (under System->Trust->Certificates)

3. Create a Client Certificate (same as step 2 but creating a Client Certificate)

4. Create an instance of OpenVPN server, using CA and Server Certificate
    (after this last step I can start OpenVPN service)

5 Add user and assign it Client Certificate (I have to create an user, save it and after that modify it and assign Client Certificate)

6. Go to Client Export and create a zip file with standard configuration

7. With this file and OpenVPN client I try to connect (from other PC on another location) but I always get 'process started and then immediately exited: []'... I have looked at OpenVPN logs but there's nothing...

Any idea?
Title: Re: Unable to generate OpenVPN client install packages
Post by: teces on February 10, 2016, 12:19:12 pm
Ok. I'm on the right way...

The first problem is the local port...

When I choose 'Use random local port' on Client Export, the .ovpn file adds the line 'lport 0' which gives the error 'Bad local port number: 0'... we need to assign another port or delete this line...
Title: Re: Unable to generate OpenVPN client install packages
Post by: AdSchellevis on February 10, 2016, 01:27:17 pm
What client are you using? some older clients are known not to support this option.
We are using Viscosoty from sparklabs mostly (https://www.sparklabs.com/viscosity/), which doesn't seem to have an issue with "lport 0"
Title: Re: Unable to generate OpenVPN client install packages
Post by: teces on February 10, 2016, 01:46:01 pm
I was triying to connect with OpenVPN Client but i haven't done it yet...

When I try to connect with OpenVPN GUI it Works perfectly... the problems is that I'm planning to use OpenVPN with some customers and I wanted anything more 'visual'...

I'm going to try with Viscosity... thanks...