Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Scholler

#1
Hi all,

I have been working so far quite good with 3 SSLVPN users which all have a /30 network in their client overrides.
IP assignment was working like a charm.

Users had the IP addresses ending with .2   .6 and .10  and /30 subnet.
Now I added another user with certificate and gave him the .14/30 in the overrides.

When I log on, it receives the .2 (from a completely different user)

What is causing this? Anyone having the same issue?
If you have an idea, please let me know...any help appreciated.

Thank you and best regards :-)


SOLUTION:
I had a typo in the "common name" field. After that had been corrected, the IP assignment was working as expected.
#2
Hi all,

in my OpenVPN config I have some users each using a different subnet (via overrides) to allow traffic to specific destinations only.
Authentication using client certificate, username and password.

Now I have a phenomena with one user.

If he uses his exported client certificate together with his OpenVPN client on Android, he can login successfully AND work on his allowed destination machines.

If he does the same on Windows 10, he can also login successfully BUT there is no traffic at all to the destination machines. I don't see anything in the firewall logs.

All IP addresses / routings correctly are correctly set in both cases.

If the user tries it on the same Windows 10 with another account (cert file, user and password), he can reach to his destinations.

What the hell is this? I do not have a clue. Anyone able to help? Thank you.
#3
Thank you pmhausen for that hint. I am confident that this will help :-)
#4
Hallo zusammen,

hab mir schon die Augen wundgesucht, vielleicht hat hier jemand eine Hilfestellung für einen Einsteiger ;-)

Hab nen OpenVPN Server auf Port 443 laufen, da ich öfters in fremden Gäste-WLANs bin und dort teilweise exotischere Ports geblockt sind.
Jetzt möchte ich auch meinen Webserver über Port 443 laufen lassen, habe aber nur eine feste IP.

Kann man das irgendwie so bauen, dass die OPNsense den Traffic so steuert, dass sie alles VPN-bezogene an den OpenVPN-Server leitet und die Web-Requests etc. an den Webserevr?

Habe ein paar schwammige Infos dazu im Netz gefunden, die mir aber nicht wirklich weiter geholfen haben.

Danke für die Hilfe!