I want to use pfSense as OpenVPN client only for PrivateInternetAccess.
I have my network 192.168.1.x and would like to keep that network on devices connected to pfSense i.e my main router (ERX) leasing IPs.
All devices connected after this pfSense box should be using PIA VPN.

Can this be accomplished? I mean is it possible to keep WAN and LAN both on 192.168.1.x as I am not using pfSense as router?

1 Answer 1


pfSense is the wrong tool. It's way too complicated and it really built around being a firewall first and a service provider second. Your EdgeRouter-X is probably the better tool for this job, and there are many examples online of how to set up openvpn client on an ERX. If that isn't your cup of tea I would recommend setting up a linux box and modifying it into a dedicated VPN gateway appliance. Install openvpn and then share the tunnel adapter, borrowing from scripts shown here.

  • 1
    Or, use the pfSense box to do everything - DHCP server for your LAN clients, OpenVPN client to your VPN provider, proxy server for your LAN, VLANs to logically separate your LAN. All you then need is a dumb switch for your LAN (or a smart switch if you want VLANs) and connect the pfSense to your Ethernet modem or router in modem-only mode...
    – Kinnectus
    Commented Oct 23, 2018 at 6:52
  • Good point. That is also an approach worth considering.
    – Andy
    Commented Oct 23, 2018 at 8:40

You must log in to answer this question.

Not the answer you're looking for? Browse other questions tagged .