OPNsense Forum

Archive => 17.7 Legacy Series => Topic started by: huukiller on October 15, 2017, 07:41:05 pm

Title: [BUG] openvpn rule pass connect.
Post by: huukiller on October 15, 2017, 07:41:05 pm
openvpn only connects when I create a floating rule releasing everything, the rule created by openvpn wizard does not work, even releasing all traffic on all interfaces opnsense continues giving timeout, only when I apply the rule in floating.

openvpn 2.4.4. en last version opnsense.

I have done several tests to release all traffic for all interfaces, and no matter how I configure, the vpn client of opnevpn only connects when the same rule created automatically by the opnevpn wizard and recreated in floating, is bug?
Title: Re: [BUG] openvpn rule pass connect.
Post by: robvh on October 16, 2017, 09:03:46 am
Here is a cookbook how to get it going: https://forum.opnsense.org/index.php?topic=4979
You could check the firewall log to see which IP address and port failed.  When I did my first install, openvpn could not resolve the name of the server.
Title: Re: [BUG] openvpn rule pass connect.
Post by: huukiller on October 18, 2017, 01:08:47 am
With these firewall rules openvpn does not connect, from the timeout, but when I put the same very restrictive rule on the floating tule I can connect to vpn and access from wan to lan normally, it's not a route problem, I work with pfsense, and I never needed it use floating rule to use openvpn.

in the attached image, when I use these rules in opnevpn, lan and wan, does not connect, when I apply the same rule of wan in floating connect normally, my question would be, because when I put the same rule in floating I connect with it, being exactly the same rule in wan.

obs: 192.168.0.3 = wan address
Title: Re: [BUG] openvpn rule pass connect.
Post by: huukiller on October 20, 2017, 12:36:49 am
Another thing is that when I use a wizard to create an openvpn rule, it creates a rule automatically in WAN, this rule does not work, it is only copied to FLOATING, and this rule is created automatically in the legend is set in direction in , but the option of direction of traffic in / out, it is only possible to configure in FLOATING, I found it strange