thanks for the video! thanks for helping me do tls/ssl on openvpn site to site. I still had a problem connecting but I solved it by changing the tunnel network and now it is picking up the connection. This can be a problem by more people but idk I fixt my problem :)
@itkb10 ай бұрын
Glad it helped
@walterhaase Жыл бұрын
Thank you! This worked perfect
@itkb Жыл бұрын
Great to hear!
@MdMozammelHossain Жыл бұрын
Thank you ! Really easy to follow and very good explanation of steps.
@itkb Жыл бұрын
Glad it was helpful!
@juliettpapa11 ай бұрын
This video helped me a lot. Thanks!!
@itkb11 ай бұрын
Glad it helped!
@Spykill. Жыл бұрын
Very thanks! Has worked perfectly
@itkb Жыл бұрын
Great to hear!
@fabriciomoura792311 ай бұрын
Thank you very much, it helped me a lot
@itkb11 ай бұрын
Glad it helped!
@pablov3rk1llАй бұрын
Thanks man, be perfect. About override, I have 30 connections client, so need I create override for all?
@itkbАй бұрын
Yes, exactly
@stephenfosu2386 Жыл бұрын
Great 👍
@itkb Жыл бұрын
Thanks for the visit
@stephenfosu2386 Жыл бұрын
Please, can you do site-to-multisites OpenVPN connection using SSL/TLS and how all the sites communicate with each other? Thanks 🙏
@artista493422 күн бұрын
First of all. Thank you for creating just wonderful videos. I followed both videos step by step (even created the same VLANs on both the head office and branch office). I was able to ping from both sides using Video 1. However when I upgrade to SSL/TLS. I can ping from the branch office to the head office but cannot ping from the head office to the branch office. Please help. I followed Lawrence Systems videos. I get the same issue.
@itkb20 күн бұрын
check Client Specific Overrides on Head Office side, check the OpenVPN rules etc.
@josemelendezprado71173 ай бұрын
hello i did follow all video step by step, it connected VPN site to site, but there aren't ping of their ip adrees between siteA and siteB, only do it ping with the ip address of the tunnel, can you help me? what is lacking?
@itkb3 ай бұрын
This video is a continuation of “Part-1” of this video series, I would advise you to watch “Part 1” first closely. This Seems you have almost done it, make sure you don't miss and create an OpenVPN rule in > Firewall / Rules / OpenVPN.
@altamirsouza834310 ай бұрын
Hello, I'm trying to configure pfSense OpenVPN SSL/TLS and while browsing the internet I found your tutorial which is the most complete I found, however I ran it several times and the last few times I decided to recreate the settings from the Shared Key and without success after carefully following the of the two videos shows ERROR TLS Error, reconnecting both at the headquarters and at the branch (I'm in the laboratory) on virtual machines I'm afraid of applying it in a production environment and deconstructing what has already been done Do you have any tips
@itkb10 ай бұрын
Glad to hear this
@celsobrito6445 Жыл бұрын
thank you very much!
@itkb Жыл бұрын
You're welcome!
@TeymurBagirov8 күн бұрын
What is the procedure to update certificates when lifetime comes to the end? You have to renew all certificates manually, export them, upload to remote branches and update?
@itkb8 күн бұрын
The procedure for renewing the certificates is the same as renewing public SSL certificates from the Certificate Authority (CA). In the same premises where CA is present, the certificate renewal is enough for the focal pfSense firewall. For branches where you have exported earlier, you have to renew it first from the same CA and follow the same procedure for export & then import it to the branch office.
@TeymurBagirov8 күн бұрын
@@itkb Please advise, how do you do it practically? For ex. you have 20 remote branches. You have to maintain list with certificates and their expire dates. So you have to setup some service which reminds you about date expiry (i know pfsense can send this notification by email for ex.). After that you have to get spare channel for update? Because if certificate update will fail at remote branch you will loose connection. When you have simple static key there is no any issue with expire. So what is the solution of update peer-to-peer SSL-TLS certificates in enterprise environment?
@itkb8 күн бұрын
“Concerns about technology often find a resolution.” I would share my best-practice advice with you. I have numerous branches around the world. Just for a portrayal, Principally every certificate has an expiry date set and possibly we could extend its expiry for more than a year, some CAs are still required to renew their certificates with new private keys. However, it is deemed needed to renew all the certificates every 1 year this is because the CA/Browser Forum has made it compulsory for all CAs not to issue any SSL for a period of more than 1 year. In all the sites, I would recommend using “Self-Signed - CA and Certificates” generated in the “pfSense firewall” with maximum expiration for all the offices/sites (must be using strong key length), at least this gives you much longer leverage in certificate renewal, unlike public certificate compulsory renewal phase.
@TeymurBagirov8 күн бұрын
@@itkb So you every year manually login to every remote branch and manually update certificates?
@itkb8 күн бұрын
Why should I wait for the end of the year 😊, comprehend the different approaches. To avoid managing certificates manually you could install the “acme” package and configure the API with your domain registrar to automate the renewal process. Watch this video for your assistance. kzbin.info/www/bejne/pnvWf3uGf6monas
@MdMozammelHossain Жыл бұрын
my pfSense intalled on a cloud VPS, and I want to use its VPN server to access a remote site. Its a industrial environment. I just have to access 10 device. Those 10 devices connected to VPN router, which supports openVPN/IPSec/WireGuard etc. I want to make a VPN tunnel such a way so I can connect to the pfSense OpenVPN server as a client and the router clso connect to pfSense OpenVPN server and I can able to access all 10 device which connect to that Router's LAN netwrok. is it possible ?
@itkb Жыл бұрын
sure, watch my pfSense OpenVPNs/IPSec related videos and you should be able to find the accurate answer.
@MdMozammelHossain Жыл бұрын
I've tired. but for site-to-site VPN connection I can't use "Client Export" function. Thus, I'm not able to connect.@@itkb
@calhta Жыл бұрын
I got the site to site up and running with your previous video - but changing to TLS breaks it for me. No traffic is passed, I cannot ping. I followed exactly 3 times, restoring to default each time. But no joy. Has something changed here with the configuration?
@itkb Жыл бұрын
Sorry to hear that, but if you follow along with the video step by step, all you need is to create a CA, Cert for your branches pfsense to add it there, sure S2S connection is established, and then check your firewall rules.
@itpugil Жыл бұрын
same for me, its says client and server is connected but i cannot access target remote subnet
@calhta Жыл бұрын
@@itpugil After a few days of confusion another video sparked a thought. Change your Tunnel Network from /24 to /30. You will be able to pass traffic that way. If I work out how to pass traffic with it above /30, I will try and remember to update that here, since obviously /30 limits it somewhat.
@itpugil Жыл бұрын
@@calhta thank you. Will test it out tomorrow. I'll let you know what comes up. This is for those out there experiencing the same issues.
@itpugil Жыл бұрын
@@calhta tested it and set tunnel network to /30 still didn't work for me. I probably have something specific to my setup that is unlike yours. Thanks for the help! Edit: I am however able to ping at both pfsense servers, so a step up from the problem I had yesterday!