VPN Client

Follow

Comments

81 comments

  • Avatar
    Geims85

    Hi Guys,

     do you know if there is any way to stop/start the 3d party VPN function using the cli instead of disabling / reenabling using the GUI ?

    Since sometimes my VPN hangs up, I would like to configure a job to automatically stop and then restart the VPN Client.

    Thanks

    Alfredo

     

    1
    Comment actions Permalink
  • Avatar
    bob

    Is it possible to do route blackholing such that if the VPN connection on the VPN network segment goes down, no traffic is routed out of the device for the VPN VLAN but other VLANs are not impacted? Thanks!

    1
    Comment actions Permalink
  • Avatar
    James Hobson

    Am I missing something - my VPN provider asks I change my password every now and then.. I go to the current active VPN profile to update the password but can't see how?

    Thanks

    1
    Comment actions Permalink
  • Avatar
    heath

    I believe you have to delete and recreate the VPN configuration if you need to change it afterwards. You might be able to change it from the CLI, but it’s not documented how anywhere how it is stored.

    This is a big gap in the management of vpn client configurations. You can’t even do basics like edit the server hostname or port after it has been created.

    1
    Comment actions Permalink
  • Avatar
    deep

    Start heavy test on using ProtonVPN! At the moment this is the way which make it work on Firewalla BLUE!
    Stay tuned!
    Platform: Router
    Protocol: UDP
    Config: Server Config >> select country and click on download near to download profile!
    INFO: Manual import profile as the Android App didn't import it automatically no matter if you click import profile! Manual import is working well and the config is readable as well!
    Name your profile and put the required username and password!

    1
    Comment actions Permalink
  • Avatar
    Neal

    Hello Firewalla Team.

    I am struggling to configure the VPN client with ProtonVPN.

    Using iOS app.

    I downloaded from ProtonVPN the ‘Router’ and ‘UDP’ config file, as Ernesto highlighted in comment above. However once imported the config and entered username and password I receive an ‘Invalid Content’ pop up in the app and cannot progress further.

    Any advice appreciated.

    Kind Regards

    **UPDATE - SOLUTION**

    I found a solution, I edited ProtonVPN's configuration file. I removed all but one of the lines that lists the same IP address but different ports.

    i.e. From this

    remote xx.xxx.xxx.xxx 80
    remote xx.xxx.xxx.xxx 443
    remote xx.xxx.xxx.xxx 4569
    remote xx.xxx.xxx.xxx 1194
    remote xx.xxx.xxx.xxx 5060

    to This

    remote xx.xxx.xxx.xxx 1194

    1
    Comment actions Permalink
  • Avatar
    heath

    For those looking for setting this up with Private Internet Access (PIA), I can confirm that it works with the OpenVPN setup, but you need to use a specific configuration as the FWG doesn't appear to support the CBC modes.

    I use the generator on the PIA site to generate an OVPN configuration file with the following:

    Region:  Pick the region you want

    Port:  Select UDP/1198 with RSA-2048 and AES-128-GCM

    I haven't tested the stronger version of this because it's a bit of a pain to change the configuration in Firewalla (you have to delete and recreate the entire profile vs. just re-importing the configuration file to existing config.

    1
    Comment actions Permalink
  • Avatar
    3pop

    Any tips for getting ProtonVPN profiles working? My profile is verified working using a different client, but when Firewalla connects it just disconnects after a minute or so. Is there a way to view the connection logs?

    1
    Comment actions Permalink
  • Avatar
    Brent Warner

    Confirmed TorGuard is working. Issues importing the OVPN file, so cut and paste the code.

    1
    Comment actions Permalink
  • Avatar
    Kawika Takayama

    My NordVPN site-to-3rd Party used to work fine.  But now when I attempt to connect up the 3rd party VPN config always fails.  Not sure why.  I have attempted to use the UPD and TCP protocols and it keeps failing.  Can someone please explain why??

     

    1
    Comment actions Permalink
  • Avatar
    Daniel Wren

    Was wondering when the ability of username and password authentication be available?

    1
    Comment actions Permalink
  • Avatar
    Support Team

    Not really. There are a couple of other places need to update.

     

    I suggest you wait for our next release, which natively supports the username and password.

     

    The release will be pushed to alpha branch in next 1-2 days.

     

    Melvin

    1
    Comment actions Permalink
  • Avatar
    Andy

    anyone using VPN Unlimited with Firewalla as a VPN client?  tia.

    https://www.vpnunlimited.com/

     

    I use VPN unlimited, have tried both Wireguard and OpenVPN. The OpenVPN config seems to work better. Wireguard, after running for a few months, will stop working and can no longer connect unless I create and download a new profile from the management console on KeepSolid (VPN Unlimited parent company).

    1
    Comment actions Permalink
  • Avatar
    Support Team

    @Augustus,

     

    Usually the ovpn file should be provided by the 3rd party VPN provider instead of writing your own.

     

    And you can import the ovpn file or create a new profile (and copy/paste the content). We'll make a video on that soon.

     

    And please be aware that this is still beta and username+password is not supported yet.

     

    Melvin

     

     

    1
    Comment actions Permalink
  • Avatar
    Bill Bradstreet

    I've been using OpenVPN for my VPN client. It has been working great.  (FYI)

    0
    Comment actions Permalink
  • Avatar
    K

    Are you considering support Wireguard as VPN client? Wireguard performs much better when CPU don't have AES-NI. 

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    The Gold has AES-NI;  The problem with OpenVPN is its single thread, while Wireguard can use multiple cores.  As for raw encryption, likely both are the same.   Wireguard VPN client will be there after Wireguard VPN server.

    0
    Comment actions Permalink
  • Avatar
    NicK Trader

    Is it possible to connect to a server that I have that is running openvpn with the gold?

    0
    Comment actions Permalink
  • Avatar
    Firewall Guy

    Hello, I am trying to configure iVPN on Gold to use the 3rd Party VPN function on the router.

    I need to upload some config file into the Firewalla App, no idea what this looks like or whats required.

    Has anyone managed to get this working for https://www.ivpn.net ?

    Any help really appreciated.

    Thanks, Donald

    0
    Comment actions Permalink
  • Avatar
    Russell Pidwell

    I finally took the time to get my PureVPN configuration sorted out on my Firewalla and figured I'd share since the Firewalla documentation is lacking.  

    • Navigate to https://support.purevpn.com/openvpn-files
    • Download the files for Linux -> For OVPN Version 2.0
    • Copy your preferred configuration file from the TCP folder (not UDP)
    • If you do not see a config file for your preferred VPN site, navigate to https://support.purevpn.com/vpn-servers and find the TCP URL for your preferred portal. Replace the line that contains the URL in your configuration file.
    • As the Firewalla documentation says, remove the two lines below from the config:
    • route-delay 0
      route 0.0.0.0 0.0.0.0
    • Configure your VPN client on the Firewalla as OpenVPN. Use the VPN subscription Username, not your login for PureVPN. See https://support.purevpn.com/how-to-easily-find-your-existing-vpn-password for instructions and finding your username/password information if you don't know it. 
    0
    Comment actions Permalink
  • Avatar
    Antonius

    Mullvad wireguard 3 connections, Cyberghost Openvpn 1 connection, and ProtonVPN 1 connection are running on 1 Firewalla Blue Plus DHCP mode serving 25 devices.

    I'm worried because the heat is quite high. Can it survive for years?

    0
    Comment actions Permalink
  • Avatar
    remotebloke

    Do we know when WireGuard client is due?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    @Luke, is it OpenVPN-based? if it is, then what kind of problems are you getting? if it is WireGuard, 1.973 and app 1.47 should support it

    0
    Comment actions Permalink
  • Avatar
    LBH

    Hello
    Please consider working with JumboPrivacy as a 3rd party VPN service provider.
    Thanks Luke

    0
    Comment actions Permalink
  • Avatar
    Andy Boes

    Just for info : I got Ivacy & VPNsecure running with remote help from the firewalla team! Works great.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    https://www.reddit.com/r/firewalla/comments/mafkvl/cyberghost_vpn_compatible_with_some_additional/

    Just wanted to offer for the @firewalla team that you can successfully configure CyberGhost VPN, but it requires similar steps to IPVanish.

    Basically you modify the .opvn file and in place of the ca line you do the ca.crt enclosed by <ca> </ca>; then rinse and repeat for cert(client.crt) and key(client.key).

    Working great for me.

    0
    Comment actions Permalink
  • Avatar
    Bob

    Can confirm ProtonVPN works on Gold as client VPN. Just went with a country profile, UDP, and the IKEv2 username/password. Didn't change anything in ovpn file. Pretty seamless so far.

    0
    Comment actions Permalink
  • Avatar
    Erik Cobben

    Hello Firewalla Team, 

    A possible upgrade for the Proton VPN part. 

    Instead of using OpenVPN opention, you also can use the Wireguard option. This way you don't have to use the OpenVPN user creadentials and only need to scan the QR-Code.

    So goto "Proton VPN -> Downloads -> WireGuard configuarion"

    1. fill-in a name

    2. Select platform: router

    3. Filter options: none and VPN accelerator

    4. Create -> QR Code

    Goyo "firewalla app -> VPN client -> Create VPN Connection -> 3rd-Party VPN"

    Choose WireGuard -> Scan QR Code

    0
    Comment actions Permalink
  • Avatar
    StarGazer

    You guys do a great job with the articles.  I would love to see how to solve VPN on mobile over Starlink.. Right now, the only way this can happen is that everyone has to support IPV6, and if anything in the chain is IPV4, it will fail due to how Starlink Nat is set up.  Having a solution to this would help anyone on Starlink.

    0
    Comment actions Permalink

Please sign in to leave a comment.