> For the complete documentation index, see [llms.txt](https://docs.acecloud.ai/knowledge-base/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.acecloud.ai/knowledge-base/tutorials/point-to-site-vpn-configuration.md).

# Point to Site VPN Configuration

## Step 1: Prerequisites

* Create a private network (VPC) without a router via Horizon.
* Navigate to Project → Network → Networks → Create Network.
* Example: Subnet - 192.168.7.0/24, Gateway IP - 192.168.7.1.

![](https://content.gitbook.com/content/VBa3yjTJ7LPbjby0TKRi/blobs/4piIJkcfl18oR4y30ljl/Unknown%20image)

![](https://content.gitbook.com/content/VBa3yjTJ7LPbjby0TKRi/blobs/oQqDCkXhwjSuuEthzI9n/Unknown%20image)

![](https://content.gitbook.com/content/VBa3yjTJ7LPbjby0TKRi/blobs/Gmwyrq0hZxJDWugUoLNJ/Unknown%20image)

## Step 2: Create a Security Group

* Navigate to Project → Network → Security Group → Create Security Group.
* Allow any protocol for the pfSense Server.

![](https://content.gitbook.com/content/VBa3yjTJ7LPbjby0TKRi/blobs/KddJIuHwobuXzquE1ehH/Unknown%20image)

## Step 3: Create a pfSense Server

* Attach both Public and Private Interfaces (e.g., Server-0).
* Assign the gateway IP.
* Disable port security of the Private Interface.

![](https://content.gitbook.com/content/VBa3yjTJ7LPbjby0TKRi/blobs/0GQUnOgRlUv5dgdyDU69/Unknown%20image)

![](https://content.gitbook.com/content/VBa3yjTJ7LPbjby0TKRi/blobs/XlNhVGN0Pq4VhddeKVB0/Unknown%20image)

## Step 4: Configure pfSense Interfaces

* Set up the LAN and WAN interfaces inside pfSense Server.

![](https://content.gitbook.com/content/VBa3yjTJ7LPbjby0TKRi/blobs/eKshhiduvsk8Gy5qsWDr/Unknown%20image)

## Step 5: Create a Temporary Windows Server

* Create a Windows Server with a private interface (e.g., Server-1).

![](https://content.gitbook.com/content/VBa3yjTJ7LPbjby0TKRi/blobs/IqZe4uEO2spFIQzD9whK/Unknown%20image)

## Step 6: Access pfSense WebGUI

* Log in using the default username and password.

![](https://content.gitbook.com/content/VBa3yjTJ7LPbjby0TKRi/blobs/P0zHtryZnbpIPERBQzEx/Unknown%20image)

## Step 7: Initial pfSense Setup

* Complete the basic setup wizard as shown in the images.

![](https://content.gitbook.com/content/VBa3yjTJ7LPbjby0TKRi/blobs/scOlj5DDA9Rons4WO4dJ/Unknown%20image)

![](https://content.gitbook.com/content/VBa3yjTJ7LPbjby0TKRi/blobs/KE765d0zP08RAkMuYUYG/Unknown%20image)

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2F1NQdyQbucJvXsxArGNr4%2Fpage4_image3.png?alt=media&amp;token=74c1da79-a128-4164-bff4-6d56c06aa776" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2Fo00CbTOLsVFrqmkSLHUW%2Fpage4_image4.png?alt=media&amp;token=ae05a54a-0aec-4790-a478-f19d2d292a73" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FsUCECWH8ZRmjVEB6hggC%2Fpage5_image1.png?alt=media&amp;token=cb7e0a5b-6aa8-4ff5-a7bc-8cac47371c8b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2F8CC9pFVulwHtlAFcsMS3%2Fpage5_image2.png?alt=media&amp;token=8e7155ae-b5d5-441f-9628-29ee703e400a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FQEhYh9d6VNWwNCKEWBGw%2Fpage5_image3.png?alt=media&amp;token=9b3252d9-11cb-461c-a0ed-715826e3af77" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FgADBx8SDfK4eZOw4HP2w%2Fpage5_image4.png?alt=media&amp;token=7b0a3271-2ec7-4d1c-b6f4-2ffc9bce84ad" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FExFC5o61JKf2PKgfLvY1%2Fpage6_image1.png?alt=media&amp;token=d6f1fca2-005c-4008-99fc-2ba2e81aa6b1" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FLE031qaYE2ifqGRsMeXt%2Fpage6_image2.png?alt=media&amp;token=0baa6e4e-d490-471a-8198-2202ef464635" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2F3b5ehe7AdOQTwQYTBwdn%2Fpage6_image3.png?alt=media&amp;token=fe0bbfa5-33dd-4ed4-a97e-5f5f11da2334" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FnWLeNyQCm9coszc6kZyY%2Fpage6_image4.png?alt=media&amp;token=a688d459-e3f3-4a36-aa44-11a4a155ccc2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FPoIge3AHmrKng6FZBksA%2Fpage6_image5.png?alt=media&amp;token=743412a9-c415-4670-bf20-73d556d47996" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2F8aLzsWd5jIvuHxXUI4oV%2Fpage7_image1.png?alt=media&amp;token=1a2cdde0-6614-4b5a-bbc0-b7826eba1902" alt=""><figcaption></figcaption></figure>

## Step 8: Set Up Certificates and OpenVPN Server

* Navigate to VPN → OpenVPN → Servers → Wizards.
* Tunnel Network: 192.168.8.0/24.
* Local Network: 192.168.7.0/24.
* Edit the server settings as needed.

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FY67j98Yjv6a0vsLOdp5D%2Fpage7_image2.png?alt=media&amp;token=50af7bbc-ba89-4c9c-939d-0bd7ae50f517" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FODiXQvOTw2ZlJ0292VTn%2Fpage7_image3.png?alt=media&amp;token=effe9102-4beb-4ad2-8d95-6bf60d85a960" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FS70ZdlPdWLKlyyHqBLUP%2Fpage7_image4.png?alt=media&amp;token=7d828cd9-57cc-43e5-951a-512e2f00e029" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2Fap5a9kz9fGl0X86QRxwN%2Fpage8_image1.png?alt=media&amp;token=ab0e72b3-90ad-4dc6-899f-fa5f86616132" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FJg5qCyi8iOlXUjKzOXCT%2Fpage8_image2.png?alt=media&amp;token=e4a4d173-8581-4cdf-9874-3514fa84a837" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FIpiTVBPWNTi2RJaz9OO8%2Fpage8_image3.png?alt=media&amp;token=af0e81e7-08dd-4fca-9d3b-42b0c8f3626a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2F8ajR8hXyoiG98RW8mIDc%2Fimage.png?alt=media&amp;token=8e9f0725-4b9d-46c7-b4d3-693473dd3eb8" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2F3o4dlzllVoKWN6V7ORav%2Fimage.png?alt=media&amp;token=37b37e79-3835-4e11-ba06-28394cb80057" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FCutT4mdpTMQfhqT2cTo9%2Fimage.png?alt=media&amp;token=d972a583-c770-43d2-a98f-f338ea385f5d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FKhEFlr5nyRxNpfGkjogl%2Fimage.png?alt=media&amp;token=ac70d365-b91e-4d2e-9b98-934a69c6b4eb" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FMvXcS3WxalQbxKmbtOIG%2Fimage.png?alt=media&amp;token=ca000dcb-b205-411b-b75e-9a24bbe3d7fd" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FRu6i9d6QMMq8pzN9BSHt%2Fimage.png?alt=media&amp;token=1fa6c1a3-bad3-4f77-8aed-7bbc8cadbce1" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FkFPV8eDS7yhWAF5B1as9%2Fimage.png?alt=media&amp;token=d6bfcd2a-ef36-4b7b-8882-955ee94f7c87" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FVhgDjVdJ2lqNogWmzTqP%2Fimage.png?alt=media&amp;token=9c91208e-da5e-4992-8668-a40cdcfebbd2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2Fsw30MmHJtr5uTeR92Ht7%2Fimage.png?alt=media&amp;token=98a3d329-fd3f-4d4e-8b57-3c463ee39d47" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FM3VBL7pkPAWhO0Bcvd7w%2Fimage.png?alt=media&amp;token=489ecb1e-96fe-4852-990a-85c7990de6f2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2F8jVjXYgGSSLVPIGLuSMl%2Fimage.png?alt=media&amp;token=2c57388d-25b0-4ff4-a821-00ba2432cc4d" alt=""><figcaption></figcaption></figure>

## Step 9: Install OpenVPN Client Export Package & Create Users

* Install 'openvpn-client-export' from System → Package Manager → Available Packages.

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FdUoarnFCvK6MBGayoS5s%2Fimage.png?alt=media&amp;token=331f90b4-5dc0-4643-b875-0db52a16bc96" alt=""><figcaption></figcaption></figure>

* Navigate to VPN → OpenVPN → Client Export to download the bundled configuration archive.

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FUmgiFVO4OMMbGSKEesXz%2Fimage.png?alt=media&amp;token=e06d0c94-b2af-4093-854f-83e3c587a297" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FzX4tAm8thaYwAkIWq9xY%2Fimage.png?alt=media&amp;token=654b7453-fcc8-4feb-b970-7f10ff9d43db" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FONh3tEd8YsMEs0RPOaFs%2Fimage.png?alt=media&amp;token=37b3c052-6602-4355-a38f-72d7f9fce691" alt=""><figcaption></figcaption></figure>

* Ensure you have a user account set up with a user certificate created. This can be completed by  \
  selecting System > User Manager > Add. Select a username and Password, then click to create a  &#x20;user certificate. Give the certificate a name and ensure that the OpenVPN\_CA that we created earlier is  &#x20;selected. Leave the rest as default and save.

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FScdkwQbgSgpcJ2r1ypaX%2Fimage.png?alt=media&amp;token=c59a6d19-b704-45b2-a040-0283d0ca75af" alt=""><figcaption></figcaption></figure>

## Step 10: Set up OpenVPN Client

* On Browser search “OpenVPN Connect Download” and download the “Download.msi” file and install it.

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FJo2YvMzu7HeZfruCQsDE%2Fimage.png?alt=media&amp;token=8a67ab74-119b-4e6b-be9c-61691ca23e00" alt=""><figcaption></figcaption></figure>

* Launch OpenVPN Connect and upload the configuration file.

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2F3H8h9RQ3t7S75W80KffA%2Fimage.png?alt=media&amp;token=0cb15ec3-9083-43c1-90cf-921743528c52" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FxmZkyNaqCzWvdo84sOlG%2Fimage.png?alt=media&amp;token=bb846f47-55bc-4af7-98a6-155fa75a251c" alt=""><figcaption></figcaption></figure>

* Enter the username and password associated with the certificate.

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FH1TUB6KhZ4J2Fakiw99k%2Fimage.png?alt=media&amp;token=12077d7f-ea9e-4e72-b21c-7fc149c380fc" alt=""><figcaption></figcaption></figure>

* Click 'Continue' to establish the connection.

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2F8DWqXgQJ6kpED8GfOz9B%2Fimage.png?alt=media&amp;token=b57428cc-085d-447b-b243-646f170ee520" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2011575719-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVBa3yjTJ7LPbjby0TKRi%2Fuploads%2FHpYJDTk8nJ3ISg1d8zUK%2Fimage.png?alt=media&amp;token=1d31bed9-f459-4a01-a392-2b903ab7923a" alt=""><figcaption></figcaption></figure>

## Step 11: Final Testing

* From the OpenVPN client, ping the pfSense LAN IP to verify connectivity.
* Verify VPN tunnel operation (client gets IP from 192.168.8.0/24).
* Ensure correct routing between VPN subnet (192.168.8.0/24) and LAN subnet (192.168.7.0/24).
* Confirm pfSense LAN interface (192.168.7.1) is reachable and responding.
