{"id":11755,"date":"2020-03-25T15:55:11","date_gmt":"2020-03-25T18:55:11","guid":{"rendered":"https:\/\/made4it.com.br\/creation-of-vpn-using-pfsense-and-openvpn\/"},"modified":"2023-03-08T15:53:10","modified_gmt":"2023-03-08T18:53:10","slug":"creation-of-vpn-using-pfsense-and-openvpn","status":"publish","type":"post","link":"https:\/\/made4it.com.br\/en\/creation-of-vpn-using-pfsense-and-openvpn\/","title":{"rendered":"Creating VPN using PFSense and OpenVPN"},"content":{"rendered":"\n<p>Hello everyone!&nbsp;<\/p>\n<p>In our <a href=\"https:\/\/www.made4it.com.br\/instalacao-de-pfsense-como-gateway-de-sua-rede\/\">last article<\/a> we learned how to install and configure PFSense, to be used as the Gateway of your network, allowing it to act with several functionalities for the network. Today we will introduce you to creating a VPN with OpenVPN, so you can access your entire internal infrastructure from anywhere you need to.<\/p>\n\n<h2 style=\"text-align: left;\">What is a VPN?<\/h2>\n\n<p>Basically, VPN stands for Virtual Private Network, and it serves as a tunnel between two connection points.<\/p>\n<p>By establishing a VPN between a computer at home and a PFSense in your company, for example, the tunnel created makes your computer act as if it were &#8216;inside&#8217; your company&#8217;s local network, allowing access to servers and equipment, if PFSense is reachable from your home machine.<\/p>\n<p>Now that we understand what VPN is all about, let&#8217;s learn how to set it up using PFSense to establish the connection between your different networks.<\/p>\n\n<h2>Configuring the VPN<\/h2>\n\n<p>We will use the PFSense Wizard for this configuration. To do this, we go in the menu <em>\n  <strong>VPN &gt; OpenVPN<\/strong>\n<\/em>. Then, click the <em>\n  <strong>Wizards tab<\/strong>\n<\/em>:<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"201\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/1-1-1024x201.png\" alt=\"\" class=\"wp-image-1183\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/1-1-1024x201.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/1-1-300x59.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/1-1-768x151.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/1-1.png 1211w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>To create the VPN, go to VPN &gt; OpenVPN &gt; Wizards.<\/figcaption><\/figure><\/div>\n\n<p>When we access the Wizard, we will select the<strong>&#8216;Type of Server<\/strong>&#8216;, as<strong>&#8216;Local User Access<\/strong>&#8216;, and we can click on &#8216;<em>\n  <strong>Next<\/strong>\n<\/em>&#8216;.<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"359\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/2-1024x359.png\" alt=\"\" class=\"wp-image-1184\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/2-1024x359.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/2-300x105.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/2-768x269.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/2.png 1192w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Here we change the Type of Server and move on.<\/figcaption><\/figure><\/div>\n\n<p>On the next screen you need to create a new Certificate Authority (Cerfificate Authority, or CA), by filling out the following fields:<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"566\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/3-1024x566.png\" alt=\"\" class=\"wp-image-1185\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/3-1024x566.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/3-300x166.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/3-768x425.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/3.png 1150w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Remember to change the location fields to suit your needs.<\/figcaption><\/figure><\/div>\n\n<p>We will use the name: <em>\n  <strong>VPN_CA<\/strong>\n<\/em>to indicate that this CA is used for the VPN. After that we are entering the size of the encryption key that will be generated. A value of <em>\n  <strong>2048<\/strong>\n<\/em> bit value is sufficient.<br>The rest can be filled in according to your data of <em>\n  <strong>Country, State, City and Organization<\/strong>\n<\/em> (or company).<\/p>\n\n<figure class=\"wp-block-image\"><img alt=\"\">The next step is the creation of a Server Certificate. To do this, simply choose the option to create a new certificate, and fill in as shown in the image (changing the location values again):<\/figure>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"516\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/4-1024x516.png\" alt=\"\" class=\"wp-image-1187\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/4-1024x516.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/4-300x151.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/4-768x387.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/4.png 1143w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Very similar to the previous one, this is the Server Certificate, not the Certificate Authority, but the settings will remain the same.<\/figcaption><\/figure><\/div>\n\n<p>Finishing up the Server Certificate, let&#8217;s make the settings for accessing the VPN itself. To do this, we choose the access interface, in our case the <em>\n  <strong>WAN<\/strong>\n<\/em>. Then we fill in the rest of the data. I will use the <em>\n  <strong>UDP only<\/strong>\n<\/em>on port <em>\n  <strong>1194<\/strong>\n<\/em> and with the description &#8216;<em>\n  <strong>VPN<\/strong>\n<\/em>&#8216;.<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"328\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/5-1024x328.png\" alt=\"\" class=\"wp-image-1188\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/5-1024x328.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/5-300x96.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/5-768x246.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/5.png 1146w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Configuration that we will use, related to the port and protocol of our tunnel.<\/figcaption><\/figure><\/div>\n\n<p>Following on the same screen are the encryption settings. In these options, we will leave <em>\n  <strong>enable TLS authentication and the automatic creation of a shared TLS key for authentication.<\/strong>\n<\/em>.<br>We can define the &#8216;<em>\n  <strong>DH<\/strong>\n<\/em>with a value of <em>\n  <strong>2048<\/strong>\n<\/em>as the default, and change the <em>\n  <strong>Encryption Algorithm<\/strong>\n<\/em> to <em>\n  <strong>AES-256-CBC<\/strong>\n<\/em>. Let&#8217;s choose the <em>\n  <strong>SHA1 (160bit)&#8217; authentication algorithm<\/strong>\n<\/em>. It is important that this option is the same on the Server side (PFSense) as on the Client side (your machine).  <br>We have our configurations as follows:<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"594\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/6-1024x594.png\" alt=\"\" class=\"wp-image-1189\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/6-1024x594.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/6-300x174.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/6-768x446.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/6.png 1142w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Encryption Settings.<\/figcaption><\/figure><\/div>\n\n<p>In the next part we have the Tunnel settings.  <br>The first field refers to the IP pool that PFSense will use for its Clients, that is, which IPs the PCs that connect to the VPN will receive for the Virtual Network. In our case, we select a \/24 block (256 IPs, 254 hosts), which is a good size. We take the block <em>\n  <strong>10.20.50.0\/24<\/strong>\n<\/em>.<br>We will fill in the option &#8216;<em>\n  <strong>Local Network<\/strong>\n<\/em>to indicate the LAN network we are trying to access so that PFSense can automatically create a route to this network. In our example, the network is <em>\n  <strong>192.168.1.0\/24<\/strong>\n<\/em>.<br>We use the compression &#8216;<em>\n  <strong>Omit Preference<\/strong>\n<\/em>compression, and enabled the &#8216;<em>\n  <strong>Inter-Client Communication<\/strong>\n<\/em>if you want the machines connected to the VPN to communicate with each other.<br>At the moment, our settings are as follows:<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"588\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/7-1024x588.png\" alt=\"\" class=\"wp-image-1190\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/7-1024x588.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/7-300x172.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/7-768x441.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/7.png 1144w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Network settings of our VPN tunnel.<\/figcaption><\/figure><\/div>\n\n<p>To finish the configuration, in the &#8216;<em>\n  <strong>Client Settings<\/strong>\n<\/em>field, we have the option <em>\n  <strong>Dynamic IP enabled<\/strong>\n<\/em>to have dynamic IPs connected. At <em>\n  <strong>Topology<\/strong>\n<\/em>we select the option <em>\n  <strong>Subnet<\/strong>\n<\/em>to have a \/24 with the IPs distributed within the block. If you want to isolate the subnet of each client, we have the net30 option, in which each client will have a separate \/30. Some older versions of Clients require it to be marked in net30, while others require it to be marked in Subnet. It is important to adapt your configuration to the Client that will be used.<br>After that we have the option to choose the DNS server for this VPN connection. Let&#8217;s leave the pattern <em>\n  <strong>quad-8<\/strong>\n<\/em> pattern and PFSense itself as DNS Servers.<br>The final settings are as shown in the picture:<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"559\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/8-1024x559.png\" alt=\"\" class=\"wp-image-1191\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/8-1024x559.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/8-300x164.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/8-768x419.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/8.png 1136w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Final configurations of our Client.<\/figcaption><\/figure><\/div>\n\n<p>On the next screen, we have the option to set a Firewall rule to allow connections from anywhere in the VPN, which we can  <em><strong>enable<\/strong><\/em>OpenVPN uses certificates to connect, and without the certificate (which must be passed directly to the person connecting) and user\/password, it is impossible to gain access to this network.<br>Just below it, the option &#8216;<em>\n  <strong>OpenVPN rule<\/strong>\n<\/em>option, we can <em>\n  <strong>enable<\/strong>\n<\/em>to allow all traffic from connected clients to pass through the VPN Tunnel.<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"400\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/9-1024x400.png\" alt=\"\" class=\"wp-image-1192\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/9-1024x400.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/9-300x117.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/9-768x300.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/9.png 1172w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Firewall Configuration. Allowing all connections is not a problem, by having certificate and user authentication with password.<\/figcaption><\/figure><\/div>\n\n<p>Finally, we finish the configuration and have the VPN ready.  <br>Now we need to create the users that will have access to the tunnel.<\/p>\n\n<h2>Creating user with certificate for VPN<\/h2>\n\n<p>To create our users, go to <em>\n  <strong>System<\/strong>\n<\/em> &gt;<em>\n  <strong>User Manager<\/strong>\n<\/em>and then go to &#8216;<em>\n  <strong>+ Add<\/strong>\n<\/em>just below the panel with your PFSense users.<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/Captura-de-Tela-2020-03-19-&#xE0;s-8.46.11-PM-1024x401.png\" alt=\"\" class=\"wp-image-1193\"\/><figcaption>PFSense user screen.<\/figcaption><\/figure><\/div>\n\n<p>In user creation, we add <em>\n  <strong>User<\/strong>\n<\/em>, <em>\n  <strong>Password<\/strong>\n<\/em> and fill in the rest with the user&#8217;s data. In this case, I will create a user &#8216;<em>\n  <strong>made4it<\/strong>\n<\/em>which we will use to connect to the network.<\/p>\n<p>Below the group selection we have a &#8216; button<em>\n  <strong>Certificate<\/strong>\n<\/em>&#8216;. You must give a<em>\n  <strong>check<\/strong>\n<\/em>on it to create the user certificates.<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"550\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/10-1024x550.png\" alt=\"\" class=\"wp-image-1195\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/10-1024x550.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/10-300x161.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/10-768x412.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/10.png 1142w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>You must select the Certificate option in order to generate the user certificate.<\/figcaption><\/figure><\/div>\n\n<p>Below the user settings we will create the certificate for our user. To do this, we create a description. Let&#8217;s use &#8216;<em>\n  <strong>made4it_cert<\/strong>\n<\/em>in our example. We select the CA created earlier and specify the same <em><strong>2048<\/strong> <strong>bits<\/strong><\/em> that we used to create it.<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"258\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/11-1024x258.png\" alt=\"\" class=\"wp-image-1196\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/11-1024x258.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/11-300x76.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/11-768x193.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/11.png 1175w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Creating a Certificate for the User.<\/figcaption><\/figure><\/div>\n\n<p>Once this is done, we can save our user.<br>To access the VPN, we need to export our certificate, using the package &#8216;<em>\n  <strong>OpenVPN Client Export<\/strong>\n<\/em>&#8216;.<\/p>\n\n<h2>Client Export Installation<\/h2>\n\n<p>Let&#8217;s go to <em>\n  <strong>System<\/strong>\n<\/em> &gt;<em>\n  <strong>Package Manager<\/strong>\n<\/em> &gt;<em>\n  <strong>Available Packages<\/strong>\n<\/em> and then, search for the package &#8216;<em>\n  <strong>openvpn-client-export<\/strong>\n<\/em>and give it a &#8216;<em>\n  <strong>+ Install<\/strong>\n<\/em>on it, then wait for the installation to finish:<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"362\" height=\"239\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/12.png\" alt=\"\" class=\"wp-image-1197\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/12.png 362w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/12-300x198.png 300w\" sizes=\"(max-width: 362px) 100vw, 362px\" \/><figcaption>Path to the Package Installer.<\/figcaption><\/figure><\/div>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"371\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/13-1-1024x371.png\" alt=\"\" class=\"wp-image-1200\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/13-1-1024x371.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/13-1-300x109.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/13-1-768x278.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/13-1.png 1175w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Package search and installation.<\/figcaption><\/figure><\/div>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"470\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/14-1-1024x470.png\" alt=\"\" class=\"wp-image-1201\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/14-1-1024x470.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/14-1-300x138.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/14-1-768x353.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/14-1.png 1193w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Properly installed package.<\/figcaption><\/figure><\/div>\n\n<p>Once the installation is complete, simply access <em>\n  <strong>VPN<\/strong>\n<\/em> &gt;<strong>\n  <em>OpenVPN<\/em>\n<\/strong> &gt;<em>\n  <strong>Client Export Utility<\/strong>\n<\/em>to start exporting the certificate.<br>On this Screen, we will leave the option &#8216;<em>\n  <strong>Host Name Resolution<\/strong>\n<\/em>&#8216; as &#8216;<em>\n  <strong>Interface IP Address<\/strong>\n<\/em>&#8216;. In &#8216;<em>\n  <strong>Verify Server CN<\/strong>\n<\/em>we can leave it at &#8216;<em>\n  <strong>Automatic<\/strong>\n<\/em>&#8216;.<\/p>\n<p>The rest can be left unchecked, so we click on &#8216;<em>\n  <strong>Save as Default<\/strong>\n<\/em>to apply the changes.<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"510\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/15-1024x510.png\" alt=\"\" class=\"wp-image-1202\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/15-1024x510.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/15-300x149.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/15-768x383.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/15.png 1152w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"510\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/16-1024x510.png\" alt=\"\" class=\"wp-image-1203\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/16-1024x510.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/16-300x149.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/16-768x383.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/16.png 1170w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Options for exporting the certificate.<\/figcaption><\/figure><\/div>\n\n<p>With the changes applied, we go to the bottom of the screen, to the user we created, and select the certificate\/client that we will export.<\/p>\n<p>In my specific case, I will download the &#8216;<em>\n  <strong>Most Clients<\/strong>\n<\/em>&#8216; into &#8216;<em>\n  <strong>Inline Configurations<\/strong>\n<\/em>because I already have a client ready. If you are going to use a Windows client, Viscosity (Windows or MacOS), or another client, just choose the file accordingly.<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"300\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/17-1024x300.png\" alt=\"\" class=\"wp-image-1204\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/17-1024x300.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/17-300x88.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/17-768x225.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/17.png 1165w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Download the certificate for connection.<\/figcaption><\/figure><\/div>\n\n<p>In my case, I will use the Client &#8216;.<em>\n  <strong>Tunnelblick<\/strong>\n<\/em>client on <em>\n  <strong>MacOS<\/strong>\n<\/em>to connect to the VPN. To make the connection, simply add the configuration files to your client, then when connecting you will be prompted for the VPN user and password, which will be from the user you created earlier, in our case, the user &#8216;<em>\n  <strong>made4it<\/strong>\n<\/em>&#8216;:<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"503\" height=\"324\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/18.png\" alt=\"\" class=\"wp-image-1205\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/18.png 503w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/18-300x193.png 300w\" sizes=\"(max-width: 503px) 100vw, 503px\" \/><figcaption>Enter the user and password you created in PFSense earlier.<\/figcaption><\/figure><\/div>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"242\" height=\"178\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/19.png\" alt=\"\" class=\"wp-image-1206\"\/><figcaption>Client trying to connect to the VPN.<\/figcaption><\/figure><\/div>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"252\" height=\"179\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/20.png\" alt=\"\" class=\"wp-image-1207\"\/><figcaption>Successfully connected!<\/figcaption><\/figure><\/div>\n\n<h2>Setting up VPN in Windows<\/h2>\n\n<p>To connect to our VPN already configured on Windows, we need a Client. We can install the OpenVPN Client using the files that PFSense itself makes available to us.<br>To do this, we go to <em>\n  <strong>VPN &gt; OpenVPN &gt; Client Export<\/strong>\n<\/em>and download the most suitable file. In this case, as I will be using the OpenVPN Client, we can select the version in <em>\n  <strong>Current Windows Installer<\/strong>\n<\/em> (For Windows 7\/8 or Windows 10).<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"http:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/1-2.png\" alt=\"\" class=\"wp-image-1212\"\/><figcaption>Remember to choose the correct version when downloading.<\/figcaption><\/figure><\/div>\n\n<p>Once the file is downloaded, we can run it and proceed with the normal installation. The File we downloaded will start the OpenVPN configuration and install our VPN connection directly, with no further configuration required.<\/p>\n<p>When the installers are finished, we can open OpenVPN by clicking on the shortcut created on the desktop, then right-click on the icon in the Toolbar (Next to the Clock), and finally click Connect and provide the user\/password data created in PFSense.<\/p>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"http:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/2-1.png\" alt=\"\" class=\"wp-image-1213\"\/><figcaption>The First icon on the left is the OpenVPN Client.<\/figcaption><\/figure><\/div>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"186\" height=\"217\" src=\"http:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/3-1.png\" alt=\"\" class=\"wp-image-1214\"\/><figcaption>Just right-click and<strong>&#8220;Connect<\/strong><\/figcaption><\/figure><\/div>\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"576\" height=\"364\" src=\"http:\/\/www.made4it.com.br\/wp-content\/uploads\/2020\/03\/4-1.png\" alt=\"\" class=\"wp-image-1215\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/4-1.png 576w, https:\/\/made4it.com.br\/wp-content\/uploads\/2020\/03\/4-1-300x190.png 300w\" sizes=\"(max-width: 576px) 100vw, 576px\" \/><figcaption>Now just enter your username and password, and we&#8217;re on the VPN!<\/figcaption><\/figure><\/div>\n\n<p>So that&#8217;s it folks, this was our guide to setting up OpenVPN using PFSense and configuring how to connect to it using the OpenVPN Client, with the files provided by PFSense itself.<br>Thanks and see you next time!<\/p>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":13,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"postBodyCss":"","postBodyMargin":[],"postBodyPadding":[],"postBodyBackground":{"backgroundType":"classic","gradient":""},"footnotes":""},"categories":[296,500,501],"tags":[503,502,505,504],"class_list":["post-11755","post","type-post","status-publish","format-standard","hentry","category-network","category-pfsense-en","category-servers","tag-pfsense-en","tag-pfsense-basics","tag-pfsense-vpn","tag-servers"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/made4it.com.br\/en\/wp-json\/wp\/v2\/posts\/11755","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/made4it.com.br\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/made4it.com.br\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/made4it.com.br\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/made4it.com.br\/en\/wp-json\/wp\/v2\/comments?post=11755"}],"version-history":[{"count":0,"href":"https:\/\/made4it.com.br\/en\/wp-json\/wp\/v2\/posts\/11755\/revisions"}],"wp:attachment":[{"href":"https:\/\/made4it.com.br\/en\/wp-json\/wp\/v2\/media?parent=11755"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/made4it.com.br\/en\/wp-json\/wp\/v2\/categories?post=11755"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/made4it.com.br\/en\/wp-json\/wp\/v2\/tags?post=11755"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}