{"id":19979,"date":"2020-04-02T16:01:10","date_gmt":"2020-04-02T16:01:10","guid":{"rendered":"http:\/\/www.firewallhardware.it\/pfsense-e-opnvpn-guida-alla-creazione-e-configurazione-di-un-server-vpn-road-warrior\/"},"modified":"2023-06-05T17:26:35","modified_gmt":"2023-06-05T15:26:35","slug":"pfsense-and-openvpn-guide-to-creating-and-configuring-a-road-warrior-vpn-server","status":"publish","type":"post","link":"https:\/\/blog.miniserver.it\/en\/pfsense\/pfsense-and-openvpn-guide-to-creating-and-configuring-a-road-warrior-vpn-server\/","title":{"rendered":"pfSense and OpenVPN: guide to creating and configuring a Road Warrior VPN server"},"content":{"rendered":"<div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1123.2px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-1\"><h3 style=\"color: #00a0df; font-size: 20px; text-align: left;\">Objective of this guide:<\/h3>\n<p>In this guide we see how to configure a <strong>RW<\/strong> (Road Warrior) <strong>VPN server via OpenVPN on pfSense<\/strong>\u00ae. The aim is to create a basic configuration to allow a correct functioning of our VPN.<\/p>\n<h3 style=\"color: #00a0df; font-size: 20px; text-align: left;\">Used Hardware:<\/h3>\n<p>This guide can be applied to all the hardware certified by us of the firewall line that you can find here: <a title=\"Firewall\" href=\"https:\/\/www.miniserver.it\/firewall\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/www.miniserver.it\/firewall<\/a><\/p>\n<h3 style=\"color: #00a0df; font-size: 20px; text-align: left;\">Software environment:<\/h3>\n<p><strong>pfSense\u00ae 2.4.x<\/strong><\/p>\n<h3 style=\"color: #00a0df; font-size: 20px; text-align: left;\">Let&#8217;s configure OpenVPN:<\/h3>\n<p>First of all, from our top menu, go to <strong>VPN<\/strong>\/<strong>OpenVPN<\/strong>\/<strong>Servers<\/strong>.<\/p>\n<p>We also proceed from the convenient Wizard that will allow us to easily create our CA (Certification Authority), the Server Certificate and the configuration of the RW <strong>VPN<\/strong> Server; these components can also be created individually.<\/p>\n<p>Let&#8217;s start by selecting Local User Access<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19767\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense1.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"275\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense1-300x103.jpg 300w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense1-768x264.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense1.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>At this point it is time to create our CA, as a necessary parameter we must enter a &#8220;Descriptive name&#8221; that will allow us to identify it, while all the other parameters can be left by default.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19769\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense2.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"568\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense2-300x213.jpg 300w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense2-768x545.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense2.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>Let&#8217;s move on to creating the Server Certificate to be associated with our <strong>VPN<\/strong> server, as perl the CA will require a &#8220;Descriptive name&#8221; and leave the other default parameters.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19771\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense3.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"579\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense3-300x217.jpg 300w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense3-768x556.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense3.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>Now the actual <strong>VPN<\/strong> server configuration.<\/p>\n<p>In the &#8220;Interface&#8221; item we select the interface on which we want our service to listen, if we have more than one WAN interface we choose the one we want to dedicate to the service, if we want later we can select multiple interfaces for greater redundancy.<\/p>\n<p>It is appropriate to consider that the port that we will choose for the <strong>VPN<\/strong> must be open on the listening interface, therefore if we are behind a Router of some ISP it will be necessary to be able to open the door to the interface of our Firewall, if instead we have the possibility of having a Public IP address directly configured on the Firewall interface will be sufficient to create an associated rule (as we will see later).<\/p>\n<p>We choose the protocol to be used and the port dedicated to the service (default for <strong>OpenVPN<\/strong> is UDP 1194).<\/p>\n<p>In the &#8220;Description&#8221; item we choose the name with which we want to identify the server.<\/p>\n<p>In the &#8220;Cryptographic Settings&#8221; section we can leave everything by default.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19773\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense4.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"919\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense4-261x300.jpg 261w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense4-768x882.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense4.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>In the &#8220;Tunnel Settings&#8221; section it will be necessary to indicate a &#8220;Tunnel Network&#8221; that we could choose at random, making sure that it is not the same as other known networks or public networks, in fact it is the virtual network that will use the <strong>VPN<\/strong>.<\/p>\n<p>In &#8220;Local Network&#8221; instead we will indicate the LAN network to which you want to give remote access, if there are multiple LAN networks to which we want to give access, you can enter them by separating them with a comma.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19775\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense5.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"483\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense5-300x181.jpg 300w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense5-768x464.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense5.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19777\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense6.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"821\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense6-36x36.jpg 36w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense6-292x300.jpg 292w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense6-768x788.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense6.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>At this point the wizard asks us if we want to insert the Firewall Rule associated with the WAN interface and the one with the OpenVPN virtual interface, by ticking both will automatically create.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19779\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense7.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"384\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense7-300x144.jpg 300w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense7-768x369.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense7.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>Let&#8217;s now see in detail the completed server configuration, as anticipated it is a basic configuration but we can always restrict security, for example by setting the maximum number of client accesses in &#8220;Concurrent connections&#8221;, or increase the level of encryption. These adjustments can affect the performance of the equipment and the connection.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19781\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense8.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"511\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense8-300x192.jpg 300w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense8-768x491.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense8.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19783\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense9.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"1029\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense9-233x300.jpg 233w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense9-768x988.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense9-796x1024.jpg 796w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense9.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19785\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense10.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"812\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense10-36x36.jpg 36w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense10-71x71.jpg 71w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense10-296x300.jpg 296w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense10-768x780.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense10.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19787\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense11.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"818\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense11-36x36.jpg 36w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense11-293x300.jpg 293w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense11-768x785.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense11.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>Below is the detail of the Firewall Rules created:<\/p>\n<ul>\n<li>For the WAN interface<\/li>\n<\/ul>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19789\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense12.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"200\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense12-300x75.jpg 300w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense12-768x192.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense12.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19791\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense13.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"902\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense13-266x300.jpg 266w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense13-768x866.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense13.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<ul>\n<li>For the <strong>OpenVPN<\/strong> interface<\/li>\n<\/ul>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19793\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense14.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"200\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense14-300x75.jpg 300w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense14-768x192.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense14.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19795\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense15.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"766\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense15-300x287.jpg 300w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense15-768x735.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense15.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p><strong>The CA.<\/strong><\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19797\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense16.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"227\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense16-300x85.jpg 300w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense16-768x218.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePFSense16.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>Now let&#8217;s see how to create the users we want to connect to in <strong>VPN<\/strong>.<\/p>\n<p>Position ourselves under System \/ User Manager \/ Users and create the username and password and User Certificate associated with the user by checking the &#8220;Certificate&#8221; &#8220;Click to create a user certificate&#8221;, you must enter a &#8220;descriptive name&#8221; to the created certificate. In this way we will have created both the user and the associated certificate in a single operation<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19964\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense17.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"934\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense17-257x300.jpg 257w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense17-768x897.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense17.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19966\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense18.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"221\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense18-300x83.jpg 300w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense18-768x212.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense18.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>In the &#8220;Certificate Manager&#8221; section we will see the certificate associated with the <strong>VPN<\/strong> server and all those associated with the users created.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19968\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense19.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"385\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense19-300x144.jpg 300w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense19-768x370.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense19.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>At this point we can export the configuration files and certificates for individual users who will use the VPN clients to connect.<\/p>\n<p>First of all it is necessary to install the package &#8220;openvpn-client-export&#8221;, to do this we can search for it by going to System\/Package Manager\/Available Packages.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19970\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense20.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"62\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense20-300x23.jpg 300w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense20-768x60.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense20.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>Once installed we will see the option added under OpenVPN \/ Client Export.<\/p>\n<p>Under &#8220;Remote Access Server&#8221; we select our created VPN server.<\/p>\n<p>In the Client Connection Behavior section we will enter the parameters with which the .ovpn configuration file will be generated for the user, in particular we recommend configuring as follows:<\/p>\n<ul>\n<li>&#8220;Host Name Resolution&#8221; on &#8220;Other&#8221;<\/li>\n<li>&#8220;Host Name&#8221; we will have to enter the Public IP address of our network<\/li>\n<li>&#8220;Verify Server CN&#8221; we can leave it by default on &#8220;Automatic&#8221; or if we have problems set it on &#8220;Do not verifythe CN server&#8221;.<\/li>\n<\/ul>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19972\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense21.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"956\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense21-251x300.jpg 251w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense21-768x918.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense21.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>Once the parameters are configured, we can export our users configuration file to be installed on the clients.<br \/>\nTo do this we have various choices, the most recommended below:<\/p>\n<ul>\n<li>&#8220;Most Clients&#8221;: genera un file .ovpn contenete sia la configurazione che i certificati e le chiavi facilmente importabile, compatibile con i client: OpenVPN per Windows, Tunnelblick per OS X<\/li>\n<li>&#8220;OpenVPN Connect&#8221;: generates an .ovpn file compatible with OpenVPN Connect Apps for Android and iOS<\/li>\n<li>&#8220;Archive&#8221;: compatible with Windows, generates an archive containing, in 3 separate files, the configuration (.ovpn), certificates (.p12) and the key (.key)<\/li>\n<li>Under the &#8220;Current Windows Installer&#8221; section we can generate self-installing and preconfigured files for Windows clients<\/li>\n<\/ul>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19974\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense22.jpg\" alt=\"VPN Configurazione pfSens\" width=\"800\" height=\"665\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense22-300x249.jpg 300w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense22-768x638.jpg 768w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardwareVPNConfigurazionePfsense22.jpg 800w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>In this guide we see how to configure a RW (Road Warrior) VPN server via OpenVPN on pfSense\u00ae.<\/p>\n","protected":false},"author":11,"featured_media":22851,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[124],"tags":[270,138],"class_list":["post-19979","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-pfsense","tag-openvpn-e-pfsense-en","tag-pfsense-en"],"_links":{"self":[{"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/posts\/19979","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/comments?post=19979"}],"version-history":[{"count":6,"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/posts\/19979\/revisions"}],"predecessor-version":[{"id":28699,"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/posts\/19979\/revisions\/28699"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/media\/22851"}],"wp:attachment":[{"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/media?parent=19979"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/categories?post=19979"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/tags?post=19979"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}