Тёмный
VMNerd
VMNerd
VMNerd
Подписаться
VMNerd Tech Tips was created to help visual learners by offering FREE step by step learning tutorials on topics that can get complicated fast. The goal for the learning tutorials is to provide high quality content with real world tips and examples for real world use cases. VMNerd Tutorials will leverage software that is typically FREE or reasonably inexpensive to everyone and can be downloaded from the creators or manufactures websites. VMNerd Tech Tips are always interested in learning something new so feel free to drop a line or two and share thoughts and if you have a topic that others may enjoy share that as well.
Комментарии
@iamrandygalvan
@iamrandygalvan 3 года назад
Hi VMNerd i have encountered problem with 1 of my new VPN Client Main Branch is established connections with site 1 and site 2. my problem is i cannot ping my site 2 while i can ping my site 1? when i tried to ping my site 2 it say "TLL Expired in Transit". can you help me please Thanks in advance
@VMNerd
@VMNerd 3 года назад
I will put together another video with multiple sites site you can use them for routing purposes ...
@hillfordh816
@hillfordh816 3 года назад
For whoever needs this! If you cannot ping/route between your various LAN networks....make sure to go onto each pfsense console and assign the interface IP again. Even after you've set up the full ipsec vpn tunnels. Then make sure to disconnect the ipsec vpn tunnel and reconnect it. In my case I followed this tutorial step by step but had my LAN interface IP set to /32 somehow. When I changed it to the correct /24 and reconnected the ipsec vpn tunnel in the web gui, it all started working. Thanks @vmnerd for a fantastic tutorial!
@jumpinjack7907
@jumpinjack7907 3 года назад
Working on school project, Thanks for the assist!
@VMNerd
@VMNerd 3 года назад
No problem!
@zangarkarabaev8583
@zangarkarabaev8583 4 года назад
thanks a lot!
@HoopHustleTV
@HoopHustleTV 4 года назад
Thanks for sharing this video, I'm using this to save bandwidth and it works for http however I want to cache ssl/https (facebook and youtube videos etc.) is there any possible way not to install certificate on every device? Thanks.
@tomsimons1461
@tomsimons1461 4 года назад
That’s one of the better how to video’s I’ve ever seen so far. Maybe, adding the part how to use RSA certificates would make it even more unique. Thanks for sharing. Well done!
@VMNerd
@VMNerd 4 года назад
Awesome, thank you!
@randomVidsandMusic
@randomVidsandMusic 4 года назад
a quick one, can i just use the same port for site 3? or i MUST create another server openvpn and copy the shared key into Site 3?
@VMNerd
@VMNerd 4 года назад
You should use another port to make sure the traffic is separate. The two different sites could kick each other out or get confused.
@hayzeproductions7093
@hayzeproductions7093 4 года назад
Thanks for the video, this is a great how to on configuring cache settings. I have a lot going on with my network including webservers under lagg, and lacp, so far after following your setup in this video i dont see any conflicting issues with my current webservers and them running their own personal ssl certificates,
@andrewasciutto1420
@andrewasciutto1420 4 года назад
I'm having a weird issue. Internally I can access the applications through the reverse proxy but externally (internet) I cannot access and I get a connection timed out error.
@VMNerd
@VMNerd 4 года назад
This may have something to do with your internet service provider "ISP" allowing access from the internet to your location.
@andrewasciutto1420
@andrewasciutto1420 4 года назад
@@VMNerd I found out what it was. I accidently had a rule on port forward settings that was allowing traffic to another part of my network. For some reason port forward rules override firewall rules and once i deleted that it was all good.
@itmatrixinc843
@itmatrixinc843 4 года назад
Great video, just too fast, you can break longer videos in a series
@VMNerd
@VMNerd 4 года назад
Thanks for the tip
@jorisbrouwer5323
@jorisbrouwer5323 4 года назад
Where did you download the DNS Manager?
@apoorvkaushik257
@apoorvkaushik257 4 года назад
Hi, i m getting this error "timeout during connect (likely firewall problem)" . M using noip free domain
@VMNerd
@VMNerd 4 года назад
What is timing out ??
@xPsIXx
@xPsIXx 4 года назад
Some ISP's block port 80 inbound. Use DNS validation method although i am not sure if that would work with noip free domain.
@moondawson2165
@moondawson2165 4 года назад
Hi, could you do a tutorial on how you setup your virtual lab for this tutorial?
@VMNerd
@VMNerd 4 года назад
I might be able to do something ... Simply I use a combination of VMWare Workstation, VMWare ESX and rented virtual private servers. Just depends on the application. I have been looking at a tool like EVENG.
@ginmardoamatpawiro9570
@ginmardoamatpawiro9570 4 года назад
I'm researching renting servers in order to set up labs like yours to practice on. Anything you would recommend based on experience. Also to give me an idea of how much $$ to put away a year/a month?
@VMNerd
@VMNerd 4 года назад
I think this warrants a video to review my lab setup. There are so many options out there and finding a setup for all of us techie folks can be a challenge when on a budget. I spent a few thousand dollars on my laptop and ssd drives and on a monthly basis I spend about $10 - $20 a month on cloud services like virtual private servers. I am always looking for other ways to save and improve my lab and testing infrastructure. Thank You for your questions ...
@nnekdmejeke120
@nnekdmejeke120 4 года назад
You say that you have a port 4002 predefined when doing the backend piece but never explained where that port was predefined or how that was done. Am I missing something here?
@VMNerd
@VMNerd 4 года назад
Just a random port that I used for the video. You can use almost any unused port.
@Oswee
@Oswee 4 года назад
I used TXT _acme_challenge records in my domain registrar console to create wildcard TLS. Works great. No need to set up dummy back-end.
@VMNerd
@VMNerd 4 года назад
Works with some providers but not all of them. I put this video together for others who may have had issues using the TXT method.
@moondawson2165
@moondawson2165 4 года назад
Must all sites have a static IP from their ISPs? I mean static public IPs
@VMNerd
@VMNerd 4 года назад
I believe dynamic is ok as long as your the vpn software can use DNS.
@moondawson2165
@moondawson2165 4 года назад
which is best site to site vpn, openvpn or ipsec
@VMNerd
@VMNerd 4 года назад
I personally like OpenVPN just a preference IPSec may require tuning when using certain types of applications like syncing active directory between multiple locations. I like to keep it simple.
@moondawson2165
@moondawson2165 4 года назад
@@VMNerd Thanks a lot.
@moondawson2165
@moondawson2165 4 года назад
Is it required, to have static public ip addresses for both or all sites?
@VMNerd
@VMNerd 4 года назад
Should not be required as long as you use a DNS host name.
@moondawson2165
@moondawson2165 4 года назад
@@VMNerd Thank you.
@mudassarali5774
@mudassarali5774 4 года назад
Excellent sir super Excellent
@VMNerd
@VMNerd 4 года назад
Thanks for your kind words.
@attilavidacs24
@attilavidacs24 4 года назад
Hello, I'm getting a bunch of loopback errors in the logs with pfsense running on ESXI vmx1: a looped back NS message is detected during DAD for fe80:2::250:56ff:feb2:55e8. Another DAD probes are being sent. Can you please help?
@VMNerd
@VMNerd 4 года назад
Every once in a while the VM just does not install correctly. Try reinstalling and follow the wizard to setup your interfaces. Make sure you install all the vNics before you install pfsense. Sometimes they get out of order based on type after install.
@chadmccluskey6465
@chadmccluskey6465 4 года назад
Great video thank you. I however can not get it to work, I am sure its a firewall issue.. I am just a little confused on the external client, what is that? Does the wan ip need to be private? do I need to have a cloud server with a static ip in order for this to work? any help would be much appreciated.. Chad
@VMNerd
@VMNerd 4 года назад
Not sure how you are configured but if you are using private networks you may need to disable the block RFC 1918 on the wan interface.
@chadmccluskey6465
@chadmccluskey6465 4 года назад
@@VMNerd thanks I got it working.. Are you going to do follow video on drive.example.com and some of the sub domains you had us create. you put out some awesome content, you must pretty busy with your day job.... I cant speak for everyone, I know I am anxiously awaiting..
@whizatit
@whizatit 4 года назад
Only problem with ANY permanent VPN on pfsense or even a VPN period, discord wont work PERIOD.
@VMNerd
@VMNerd 4 года назад
Bypass it
@evlarette
@evlarette 4 года назад
Thank you so much,, its help me a lot, I just get stuck when de WAN CARP status is Master and Backup, but the LAN CARP status is Master on both
@VMNerd
@VMNerd 4 года назад
Honestly I am not sure when I see master master I reboot the secondary.
@billsecond1
@billsecond1 4 года назад
Great setup. I was hoping to see HAProxy configured for multiple domains on a single IP address with this configuration.
@VMNerd
@VMNerd 4 года назад
This is a video I want to create in the future and add multiple applications and change/obfuscate the real server type as an example.
@tel3d
@tel3d 4 года назад
Thank you! was exactly what i was looking for. worked
@VMNerd
@VMNerd 4 года назад
Your very welcome
@MrGuitarSmoker
@MrGuitarSmoker 4 года назад
Hi ! Thank you for the video. I problem i have though is that when i add an AD group under Administration/Access Control/Global Permissions, and that i put myself in that group (In AD directly) i can connect, but if i remove myself (Still in AD) from that group (Group that is still in Global Permissions but with no one in it) i still can connect ! I can't do much things as some of the windows are grayed but i'm still able to connect... Do you have any ideas pls ?
@VMNerd
@VMNerd 4 года назад
Let me check
@MrGuitarSmoker
@MrGuitarSmoker 4 года назад
@@VMNerd it is ok, i found out what was my problem My AD VM did not have vmware tools installed
@walterleon5581
@walterleon5581 4 года назад
Saludos amigo y Gracias por el video, tengo una pregunta, como le coloco el tiempo restante que lleva conectado un amigo en portal cautivo, en pfsense (claves wifi pero con VOUCHERS) que les muestre, (Ejemplo: su tiempo restante es: 8minutos y 10segundos.) No encuentro solucion en los foros pfsense, Espero me ayuden, se los agradeceria inmensamente. (yo uso pfsense version 2.4.4 p3)
@ChrismondJeanJacques
@ChrismondJeanJacques 4 года назад
Hi VMnerd team, I am using pfsense as firewall and I am having issue unbound DNS. It stopped working and I have this error message: The generated config file cannot be parsed by unbound. Please correct the following errors: /var/unbound/test/unbound_server.pem: No such file or directory [1575213668] unbound-checkconf[65410:0] fatal error: server-cert-file: "/var/unbound/test/unbound_server.pem" does not exist Can you please help me to fix the issue. Thank you Chrismond
@VMNerd
@VMNerd 4 года назад
Hey Chris, Check and validate that the SSL you are trying to bound to in the local CA section. If not check and see if you can generate a new one using the ACME plugin.
@phillippc
@phillippc 4 года назад
Hi VMNerd, up to now im using a debian machine to do all my routing and open vpn site to site, but im running into huge networking performance issues. Hence ive been reading up and im going to try using pfsense instead. Ive read a lot about LRO and TRO, i was wondering if you knew anything about this. On this kind of a setup with the esx host being the remote i want to connect via site to site openvpn, have you run into this scenario where even though oyu have a gigabit connection the routing eats up and all i get is 30-40mbit Thanks in advance!
@VMNerd
@VMNerd 4 года назад
I have not put much research into this as I do have enough data going through my systems that create that type of issue. I am assuming TCP Segmentation Offload and Large Receive Offload is what you are talking about in VMWare. In VMWare you still have hardware limits that could be bogging down your system and not giving the desired throughput. I am interested in learning more about your scenario please reply with some steps for me to try and create what you are seeing.
@vipintripathi745
@vipintripathi745 4 года назад
Excllent video , all in details with patience , thanks
@VMNerd
@VMNerd 4 года назад
Thank You for you kind words on this video.
@gtgtilak
@gtgtilak 4 года назад
Do you know how can we configure site to site with multi wan ? for example i have 2 wan links at site 1 and 2 wan links at site 2 . Trying to set up multiwan for ipsec failover.
@VMNerd
@VMNerd 4 года назад
I do not know how to setup with multi WAN but I am assuming you can use route metrics to control which path then if one goes down the other can take over ...
@VMNerd
@VMNerd 4 года назад
Maybe I can look into it ...
@gtgtilak
@gtgtilak 4 года назад
@@VMNerd Interesting can you guide me how to do this ? Thank you.
@jimmatrix7244
@jimmatrix7244 5 лет назад
Good instructional video. Off topic but I would like to ask how to configure this scenario; Existing nodes connected through ENDIAN openvpn. Now I would like another layer of VPN with pfsense. The packets should go through Endian VPN > Pfsense VPN to the internet. Any idea?
@VMNerd
@VMNerd 4 года назад
I think your biggest issue will be MTU inside the encapsulated tunnel and the devices that use it but should be doable. Might I ask why you want to route through another VPN inside a VPN? I am trying to envision a use case.
@jimmatrix7244
@jimmatrix7244 4 года назад
​@@VMNerd Just a wild idea that it may add more security. Have not set it up yet.Perhaps, it is similar to site to site VPN, I don't know much technical detail. Thanks for the reply.
@waynemariette682
@waynemariette682 5 лет назад
Great video and just what i was looking for, however i have an issue....since i dont use google domains..how do i find the similar thing in Cpanel. I.E i have my own domain and static IP from ISP
@VMNerd
@VMNerd 5 лет назад
In the video I used google domain but there are other options for dns entries. Just check the pull down and find one that matches hosting environment. The one you are looking will be whoever your registrar for DNS. I will look in the am for cpanel support it might work.
@jameseduard2092
@jameseduard2092 5 лет назад
VMNerd is it possible to make briidge with ipsec tunnel? HQ - Voip server and has dhcp server Branch - connect via ipsec tunnel but the ipphone can get ip from external dhcp from HQ? is this possible? can you help me please thanks
@VMNerd
@VMNerd 5 лет назад
The answer is yes ... you must create interface on IPSec tunnel. Once you do that you should be able to forward DHCP requests to IP address.
@MakoaSantarini
@MakoaSantarini 5 лет назад
That was awesome. What happens when you change the IP associated with the certificate? Do you need to redistribute updated certificates?
@VMNerd
@VMNerd 5 лет назад
The IP is not associated with the certificate. If you change the IP as long as it resolves to your IP new or something else it should switch with no change to the client.
@lkfng
@lkfng 5 лет назад
F@#KING AWESOME! This will help on a current project.
@VMNerd
@VMNerd 5 лет назад
Great News !! I am glad the video provides value.
@lkfng
@lkfng 5 лет назад
@@VMNerd Will, there be any new videos coming?
@VMNerd
@VMNerd 5 лет назад
I have something coming soon
@lkfng
@lkfng 5 лет назад
@@VMNerd Looking forward.
@SkylarkTorch
@SkylarkTorch 5 лет назад
As a young professional building up a homelab - I have very little experience in PFSense or designing these things for myself. I didn't find the video very useful from an architecting standpoint, but I feel that the visio illustration was inspirational for my own notekeeping. I also appreciated the brief trip through some interface menus; the chance to see settings that don't actually break everything.
@VMNerd
@VMNerd 5 лет назад
Thank You for your feedback. I am glad some of the video provides value.
@rtucker8837
@rtucker8837 5 лет назад
Awesome tutorial. I have this mostly working (traffic is going out of the VPN), however I have several interface assigments (VLANS). When I set the gateway to the regular WAN on some of those assignments, I get out to the internet and see my usual public IP but my devices can't communicate with each other internally. Any idea what would cause that? Thanks again for the tutorial.
@VMNerd
@VMNerd 5 лет назад
You need a rule in front of the VPN rule that allows the network to talk to the network .... without the VPN routing on it.
@JoseMiguelGomezManzano
@JoseMiguelGomezManzano 5 лет назад
when i create the certificate i get the following error Verify error:Fetching xxxxxx.xxxxx.net/.well-known/acme-challenge/N7ogiIDbYZO8irWrhnhnFwk9r3e1-wRC7NkmTaoNRLE: Error getting validation data
@VMNerd
@VMNerd 5 лет назад
I am curious of the HAProxy config and I am assuming that you followed the video. If you would be willing to share your config let me know. You can send a response here and only I will see it make sure you put in the comments not to approve it.
@LifeofAedan
@LifeofAedan 5 лет назад
I only have two interfaces. Is there a way I can program it to only send people on DHCP to the portal? I am renting our house out and want people to have to agree to a terms of service.
@VMNerd
@VMNerd 5 лет назад
You might be able to allow specific ip addresses as a bypass in the Captive Portal section.
@LeadasTwoKings
@LeadasTwoKings 5 лет назад
With this setup. Using the 'normal vpn user' will I be able to connect to the pfSense web portal when connected to the VPN? I'm about to Colocate my server and I'm thinking that this would be the perfect setup for me.
@VMNerd
@VMNerd 5 лет назад
The answer is yes just make sure you have firewall that allows communication before the rule that forces traffic down the vpn.
@carlosfagomes
@carlosfagomes 5 лет назад
The content is great--I love your introductions with diagrams and objectives--but please, get a better microphone. Are you planning on making a video about IDS/IPS packages for pfSense? That would be very interesting!
@VMNerd
@VMNerd 5 лет назад
Thank You for your feedback. I have gone through many microphones with not much luck. I will continue to search for a better microphone.
@hassibwardak3645
@hassibwardak3645 5 лет назад
Please make a video on pfsense port forwarding
@VMNerd
@VMNerd 5 лет назад
Can you provide a use case or scenario?
@phainesthai
@phainesthai 5 лет назад
Should you have a valid certificate when you setup your DNS resolver, or can you use a self signed/generated certificate? Would you not get an error or failure? What I'm asking is would the certificate only be used for encryption or validation as well when connecting/requesting to secure DNS? I have done everything as you explained, but I cant seem to capture packets to see whether any packets are sent on port 53 when making a DNS request.
@VMNerd
@VMNerd 5 лет назад
Don’t think that is necessary as the cert is used to encrypt the traffic. It can be self signed as long as the remote end is valid. Can you tell me your layout for packet capturing.
@phainesthai
@phainesthai 5 лет назад
VMNerd tbh, I’ve tried to use wireshark gui once and couldn’t make anything out about it, despite me having CCNA certification. And not tried it on CLI either. Maybe you can make a tut about how to use it and what to look for. I really like your tutorials. Like the explanation with outline in the beginning and then the conclusion at the end with what’s been covered.
@VMNerd
@VMNerd 5 лет назад
I can add that to a growing list of videos. Thank You for your feedback it is well received.
@Apkabhai-Cricketer
@Apkabhai-Cricketer 5 лет назад
not able to block gmail though....any suggestion?
@VMNerd
@VMNerd 5 лет назад
Google can be tricky as they use lots of DNS entries. You can perform a dns lookup and block the ip addresses.
@snakeshawn1118
@snakeshawn1118 5 лет назад
I like your video
@VMNerd
@VMNerd 5 лет назад
Thank Your feedback.
@PeteKowalsky
@PeteKowalsky 5 лет назад
This is really good - BUT, what if I want to block ANY off-LAN DNS (i.e. call home) from working at all in the first place? It's cool to put it into a TLS-wrapped query, but off-net DNS can be leveraged for attacks as well and for "call home" stuff like you mentioned. Personally, I block all DNS queries destined other than to my pfSense DNS Resolver... ;) Just sayin. Diagram reveal in PowerPoint is nice. Keep up the great work!
@VMNerd
@VMNerd 5 лет назад
The real driver behind this video is to keep you ISP from snooping on your traffic based on your DNS queries. Today they can intercept your traffic even if you are using VPN as your DNS might be using your onsite DNS server revealing what content you are looking at.
@PeteKowalsky
@PeteKowalsky 5 лет назад
@@VMNerd I totally agree and I have since configured my setup very similarly... I know you were doing it to illustrate but on an actual setup you can just use PFtop with the simple filter on the destination port in the out direction for all those DNS queries.
@VMNerd
@VMNerd 5 лет назад
I don't see why not .. You are right I used that so people can see what it looks like once it leaves the WAN from the ISP perspective. It's good to see it from that view to show physical separation it can minimize confusion.
@PeteKowalsky
@PeteKowalsky 5 лет назад
Fantastic video - I like the "out on the veranda at night" ambience with the crickets and stuff. New audio config / setup you have is much appreciated. More importantly, this is a great idea that would easily allow me to bypass any - er - "encumberances" - to streaming blacked-out sporting events, even while on the road, hahaha! :)
@VMNerd
@VMNerd 5 лет назад
I got a cheap micro phone and the room I was in was very hot and so I cracked the window while I was recording. Thank You for the feedback.
@PeteKowalsky
@PeteKowalsky 5 лет назад
GREAT content - I'm a fan! :) Nice work - concise and to the point as it can be. Can you integrate ACME (LetsEncrypt) trusted certs with OpenVPN + NPS? How would that work - the same? This setup is what I'd love to have for myself...
@VMNerd
@VMNerd 5 лет назад
Using your own CA is probably best as the OpenVPN will leverage the CA to pre talk before the user name and password is exchanged. You can use one certificate for anyone and use NPS with any Username and Password selected.
@PeteKowalsky
@PeteKowalsky 5 лет назад
Hey - VERY good video and extremely helpful. Liked and subscribed!
@VMNerd
@VMNerd 5 лет назад
I am glad you enjoyed the content and thank you for the likes, Is there other things you maybe interested in?