If you checked the 2 boxes at the end of the OpenVPN wizard, the rules must have been created in the firewall.
However, to check that these have been created, go to: Firewall -> Rules.
In the "WAN" tab, you will see that an "OpenVPN OpenVPN server for remote access wizard" rule has been created to allow IPv4 network traffic to UDP port 1194 (OpenVPN) of the pfSense WAN address.
Which allows OpenVPN clients to access your OpenVPN server from the Internet.
In the "OpenVPN" tab of the firewall, you will see that an "OpenVPN OpenVPN server for remote access wizard" rule has been created to allow all IPv4 network traffic into the OpenVPN tunnel.
To change the server mode and more specifically the way your users will be authenticated, go to: VPN -> OpenVPN.
In the "Servers" tab, click on the small pencil to the right of your OpenVPN server.
In the "Configuration Mode" section, locate the "Server mode" setting.
As you can see, at the moment your customers must log in with a local account in pfSense (User Auth) and have a user type certificate (SSL) in their account on pfSense.
If you wish, you can choose one of the other "Remote Access" modes:
Warning : only requiring the SSL certificate can cause problems when a laptop on which it was located is stolen, for example.
If you think that a certificate has been understood (during the theft of a computer where an OpenVPN client was configured, for example), you can revoke the certificate concerned so that it is no longer valid.
To do this, go to: System -> Cert. Manager.
Warning : you will then need to tell your OpenVPN server to use the revocation list created. Because by default, there is none.
To do this, locate the "Peer Certificate Revocation list" parameter in the configuration of your OpenVPN server.
In the "Certificate Revocation" tab, you will be able to select a certificate authority (CA) for which you want to create a new revocation list.
To add a user account on pfSense, go to: System -> User Manager.
In the "Users" tab, click: Add.
Specify a Username and Password for this user.
Then, check the "Click to create a user certificate" box for the "Certificate" parameter.
In the "Create Certificate for User" section that appears, indicate:
Click Save.
Your user has been created.
Firewall 8/8/2025
Firewall 6/11/2025
Firewall 9/17/2025
Firewall 8/27/2025
Pinned content
Contact
® InformatiWeb-Pro.net - InformatiWeb.net 2008-2022 - © Lionel Eppe - All rights reserved.
Total or partial reproduction of this site is prohibited and constitutes an infringement punishable by articles L.335-2 and following of the intellectual property Code.
No comment