Bookmark

How to Connect NordVPN and Isolate VPN Traffic on a Separate AP (Part 2)

Outdated
This is an advanced configuration. You should understand the OPNsense menus and have a recovery path before changing VPN routing.

See Part 1 — Add a VLAN and assign it to an interface .


II. Configure NordVPN on OPNsense

1. Configure the VPN client

Open SystemTrustAuthorities, click +Add, and create a certificate authority.

Enter:

  • Descriptive Name: NordVPN_CA
  • Method: Import an existing Certificate Authority
  • Certificate data: paste the following certificate.
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
-----BEGIN CERTIFICATE-----
MIIFCjCCAvKgAwIBAgIBATANBgkqhkiG9w0BAQ0FADA5MQswCQYDVQQGEwJQQTEQ
MA4GA1UEChMHTm9yZFZQTjEYMBYGA1UEAxMPTm9yZFZQTiBSb290IENBMB4XDTE2
MDEwMTAwMDAwMFoXDTM1MTIzMTIzNTk1OVowOTELMAkGA1UEBhMCUEExEDAOBgNV
BAoTB05vcmRWUE4xGDAWBgNVBAMTD05vcmRWUE4gUm9vdCBDQTCCAiIwDQYJKoZI
hvcNAQEBBQADggIPADCCAgoCggIBAMkr/BYhyo0F2upsIMXwC6QvkZps3NN2/eQF
kfQIS1gql0aejsKsEnmY0Kaon8uZCTXPsRH1gQNgg5D2gixdd1mJUvV3dE3y9FJr
XMoDkXdCGBodvKJyU6lcfEVF6/UxHcbBguZK9UtRHS9eJYm3rpL/5huQMCppX7kU
eQ8dpCwd3iKITqwd1ZudDqsWaU0vqzC2H55IyaZ/5/TnCk31Q1UP6BksbbuRcwOV
skEDsm6YoWDnn/IIzGOYnFJRzQH5jTz3j1QBvRIuQuBuvUkfhx1FEwhwZigrcxXu
MP+QgM54kezgziJUaZcOM2zF3lvrwMvXDMfNeIoJABv9ljw969xQ8czQCU5lMVmA
37ltv5Ec9U5hZuwk/9QO1Z+d/r6Jx0mlurS8gnCAKJgwa3kyZw6e4FZ8mYL4vpRR
hPdvRTWCMJkeB4yBHyhxUmTRgJHm6YR3D6hcFAc9cQcTEl/I60tMdz33G6m0O42s
Qt/+AR3YCY/RusWVBJB/qNS94EtNtj8iaebCQW1jHAhvGmFILVR9lzD0EzWKHkvy
WEjmUVRgCDd6Ne3eFRNS73gdv/C3l5boYySeu4exkEYVxVRn8DhCxs0MnkMHWFK6
MyzXCCn+JnWFDYPfDKHvpff/kLDobtPBf+Lbch5wQy9quY27xaj0XwLyjOltpiST
LWae/Q4vAgMBAAGjHTAbMAwGA1UdEwQFMAMBAf8wCwYDVR0PBAQDAgEGMA0GCSqG
SIb3DQEBDQUAA4ICAQC9fUL2sZPxIN2mD32VeNySTgZlCEdVmlq471o/bDMP4B8g
nQesFRtXY2ZCjs50Jm73B2LViL9qlREmI6vE5IC8IsRBJSV4ce1WYxyXro5rmVg/
k6a10rlsbK/eg//GHoJxDdXDOokLUSnxt7gk3QKpX6eCdh67p0PuWm/7WUJQxH2S
DxsT9vB/iZriTIEe/ILoOQF0Aqp7AgNCcLcLAmbxXQkXYCCSB35Vp06u+eTWjG0/
pyS5V14stGtw+fA0DJp5ZJV4eqJ5LqxMlYvEZ/qKTEdoCeaXv2QEmN6dVqjDoTAo
k0t5u4YRXzEVCfXAC3ocplNdtCA72wjFJcSbfif4BSC8bDACTXtnPC7nD0VndZLp
+RiNLeiENhk0oTC+UVdSc+n2nJOzkCK0vYu0Ads4JGIB7g8IB3z2t9ICmsWrgnhd
NdcOe15BincrGA8avQ1cWXsfIKEjbrnEuEk9b5jel6NfHtPKoHc9mDpRdNPISeVa
wDBM1mJChneHt59Nh8Gah74+TM1jBsw4fhJPvoc7Atcg740JErb904mZfkIEmojC
VPhBHVQ9LHBAdM8qFI2kRK0IynOmAZhexlP/aT/kpEsEPyaZQlnBn3An1CRz8h0S
PApL8PytggYKeQmRhl499+6jLxcZ2IegLfqq41dzIjwHwTMplg+1pKIOVojpWA==
-----END CERTIFICATE-----

Leave Certificate Private Key empty and keep Serial for next certificate at its default.

 Screenshot
NordVPN OPNsense certificate

Click Save.

Open VPNOpenVPNClients and click +Add.

General information:

FieldValue
DisabledLeave unchecked
DescriptionFor example NordVPN_JP
Server modePeer to Peer (SSL/TLS)
ProtocolUDP4, or TCP4 if required
Device modetun
InterfaceVPN_LAN
Remote serverGet a hostname from https://nordvpn.com/servers/tools/ , for example vn21.nordvpn.com; use port 1194 for UDP or 443 for TCP
Retry DNS resolutionChecked
Proxy host / portEmpty
Proxy AuthenticationNone
Local portEmpty

User authentication:

FieldValue
Username/passwordNordVPN username and password
Renegotiate timeEmpty

Cryptographic settings:

  • Enable authentication of TLS packets: Enabled.
  • Disable automatic TLS-key generation and paste the static key below.
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
-----BEGIN OpenVPN Static key V1-----
e685bdaf659a25a200e2b9e39e51ff03
0fc72cf1ce07232bd8b2be5e6c670143
f51e937e670eee09d4f2ea5a6e4e6996
5db852c275351b86fc4ca892d78ae002
d6f70d029bd79c4d1c26cf14e9588033
cf639f8a74809f29f72b9d58f9b8f5fe
fc7938eade40e9fed6cb92184abb2cc1
0eb1a296df243b251df0643d53724cdb
5a92a1d6cb817804c4a9319b57d53be5
80815bcfcb2df55018cc83fc43bc7ff8
2d51f9b88364776ee9d12fc85cc7ea5b
9741c4f598c485316db066d52db4540e
212e1518a9bd4828219e24b20d88f598
a196c9de96012090e333519ae18d3509
9427e7b372d348d352dc4c85e18cd4b9
3f8a56ddb2e64eb67adfc9b337157ff4
-----END OpenVPN Static key V1-----
  • Peer Certificate Authority: NordVPN_CA.
  • Client Certificate: None; username and password are used.
  • Encryption Algorithm: AES-256-CBC.
  • Auth Digest Algorithm: SHA512.
  • Hardware Crypto: No hardware acceleration.
 Screenshot
Cryptographic settings

Tunnel settings:

FieldValue
IPv4/IPv6 tunnel networkEmpty
IPv4/IPv6 remote networksEmpty
Limit outgoing bandwidthEmpty
CompressionEnable with adaptive compression
Type-of-serviceUnchecked
Disable IPv6Checked if IPv6 is not used
Don't pull routesUnchecked
Don't add/remove routesChecked
 Screenshot
Tunnel settings

Advanced configuration: paste:

1
2
3
4
5
6
7
8
remote-random;
tun-mtu 1500;
tun-mtu-extra 32;
mssfix 1450;
persist-key;
persist-tun;
reneg-sec 0;
remote-cert-tls server;

Set Verbosity level to 3 or leave it at 1, then click Save.

2. Add an interface for the VPN

  • Open InterfacesAssignments and click +. The interface is usually named ovpnc1.
  • Edit the new interface and enable it.
FieldValue
DescriptionNordVPN or another useful name
Block private networksUnchecked
Block bogon networksUnchecked
IPv4 Configuration TypeNone
IPv6 Configuration TypeNone
MAC / MTU / MSSEmpty

Leave DHCP client configuration unchanged. Click Save and Apply changes.

 Screenshot
VPN interface

Configure the firewall and gateway

  • Open FirewallNATOutbound and select Hybrid outbound NAT rule generation. Save and apply.
    Outbound firewall
  • Under FirewallRulesVPN_LAN, edit Allow VPN_LAN network and select gateway NORDVPN_VPNV4 under Advanced features.
    VPN gateway
  • Add another rule with Source VPN_LAN net and Destination VPN_LAN Address, then save and apply.
  • Open SystemGatewaysSingle, edit NORDVPN_VPN6, disable it, and apply.
  • Open VPNOpenVPNConnection Status. The connection should show up.
 Screenshots
VPN up
Dashboard

III. Configure the AP and separate VPN Wi-Fi

Follow the OpenWrt AP Mode and Guest VLAN guide , changing the VLAN ID to the one used for VPN_LAN.

Good luck. If you find a missing step or get stuck, leave a comment with the exact screen and error.


0 Bình luận

Góp Ý / Bình Luận / Đánh giá