pages:howtos:pfsense:simple-site-to-site-vpn-with-pfsense-and-openvpn
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
pages:howtos:pfsense:simple-site-to-site-vpn-with-pfsense-and-openvpn [2021/03/14 17:31] – mischerh | pages:howtos:pfsense:simple-site-to-site-vpn-with-pfsense-and-openvpn [2021/12/09 23:28] (current) – rokkitlawnchair | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | {{tag> | + | {{tag>howto openvpn pfsense sitetosite vpn apu1c4 pcengines}} |
====== simple site to site VPN with pfSense and OpenVPN ====== | ====== simple site to site VPN with pfSense and OpenVPN ====== | ||
I just had to set up a simple site to site VPN between a site with a fixed IP (SITE-B) and a site with a dynamic IP (SITE-A). Both routers are running the ‘Community Edition’ of [[https:// | I just had to set up a simple site to site VPN between a site with a fixed IP (SITE-B) and a site with a dynamic IP (SITE-A). Both routers are running the ‘Community Edition’ of [[https:// | ||
Line 23: | Line 23: | ||
* In the ‘**General Information**‘-section: | * In the ‘**General Information**‘-section: | ||
+ | * **Disable this server:** ☐ | ||
+ | * **Server mode:** Peer to Peer (Shared Key) | ||
+ | * **Protocol: | ||
+ | * **Device Mode:** tun | ||
+ | * **Interface: | ||
+ | * **Local port:** set it to the port you want the local OpenVPN server to listen on. Default is ‘// | ||
+ | * **Description: | ||
+ | * In the ‘**Cryptographic Settings**‘-section: | ||
+ | * **Automatically generate a shared key:** ☒ | ||
+ | * **Encryption Algorithm: | ||
+ | * **Auth digest algorithm: | ||
+ | * **Hardware Crypto:** No Hardware Crypto Acceleration (this is PC Engines APU specific, if your hardware has crypto support – enable it) | ||
+ | * In the ‘**Tunnel Settings**‘-Section: | ||
+ | * **IPv4 Tunnel Network:** 10.4.10.0/ | ||
+ | * **IPv6 Tunnel Network:** leave empty | ||
+ | * **IPv4 Remote network(s): | ||
+ | * **IPv6 Remote network(s): | ||
+ | * **Concurrent connections: | ||
+ | * **Compression: | ||
+ | * **Type-of-Service: | ||
+ | * **Duplicate Connection: | ||
+ | * **Disable IPv6:** ☒ Don’t forward IPv6 traffic | ||
+ | * In the ‘**Advanced Configuration**‘-section: | ||
+ | * **Custom options:** leave empty | ||
+ | * **Verbosity Level:** default | ||
+ | * Click on ‘**Save**‘-button | ||
- | ^ Setting | + | You should now be forwarded |
- | | Disable this server | ☐ | | + | {{ : |
- | | Server mode | Peer to Peer (Shared Key) | | + | |
- | | Protocol | + | |
- | | Device Mode | tun | | + | |
- | | Interface | + | |
- | | Local port | set it to the port you want the local OpenVPN server | + | |
- | | Description | + | |
- | * In the ‘Cryptographic Settings‘-section: | + | ===== Configure |
- | * Automatically generate a shared key: ???? | + | * Navigate to ‘**VPN – OpenVPN**‘ |
- | * Encryption Algorithm: AES-256-CBC (256 bit key, 128 bit block) | + | {{ :pages: |
- | * Auth digest algorithm: RSA-SHA512 (512-bit) | + | |
- | * Hardware Crypto: No Hardware Crypto Acceleration (this is PC Engines APU specific, if your hardware has crypto support – enable it) | + | |
- | * In the ‘Tunnel Settings‘-Section: | + | * On the ‘**Clients**‘-tab click the ‘**+ Add**‘-button to add a new OpenVPN client |
- | * IPv4 Tunnel Network: 10.4.10.0/ | + | {{ :pages: |
- | * IPv6 Tunnel Network: leave empty | + | |
- | * IPv4 Remote network(s): 10.3.2.0/24 (this is a comma separated list for all the networks | + | |
- | * IPv6 Remote network(s): leave empty | + | *In the ‘**General Information**’-section: |
- | * Concurrent connections: 1 | + | * Disable |
- | * Compression: | + | * Server mode: Peer to Peer (Shared Key) |
- | * Type-of-Service: | + | * Protocol: UDP |
- | * Duplicate Connection: ☐ Allow multiple concurrent connections from clients using the same Common Name | + | * Device mode: tun |
- | * Disable IPv6: ???? Don’t forward IPv6 traffic | + | * Interface: Set to whatever external interface |
- | | + | * Local port: leave empty |
- | * Custom options: leave empty | + | * Server host or address: Set to the FQDN or IP address |
- | * Verbosity Level: default | + | * Server port: Set to the same port you have set in the server setup at SITE-B. Default is ‘1194‘. |
- | * Click on ‘Save‘-button | + | Proxy host or address: leave empty |
+ | Proxy port: leave empty | ||
+ | Proxy Auth. – Extra options: none | ||
+ | Infinitely resolve server: ???? | ||
+ | | ||
+ | | ||
+ | Peer Certificate Authority: nothing to do here | ||
+ | Peer Certificate Revocation list: nothing to do here | ||
+ | | ||
- | You should now be forwarded | + | Go back to SITE-B router. If you haven’t left the window open, navigate to ‘VPN – OpenVPN‘ |
+ | ---- | ||
+ | ~~DISCUSSION~~ |
pages/howtos/pfsense/simple-site-to-site-vpn-with-pfsense-and-openvpn.1615743064.txt.gz · Last modified: 2021/03/14 17:31 by mischerh