pfSense & OPNsense
OpenVPN client instance with certificates.
pfSense and OPNsense can route your whole network through RealVPN with an OpenVPN client. The flow: import certificates → create the client → assign an interface → outbound NAT.
What you need
- pfSense CE 2.6+ / Plus, or OPNsense 23.x+
-
Get your OpenVPN certificates
On realvpn.io/settings choose OpenVPN UDP, a location and New manual device, then press Generate config. RealVPN.ovpn is saved to your Downloads.
Then press Certificates (.zip) and unzip it — you’ll need
ca.crt,client.crt,client.keyand the server name inserver.txt.
-
Import the CA and the client certificate
pfSense: System → Cert Manager → CAs → Add → Import an existing Certificate Authority, paste
ca.crt. Then Certificates → Add/Sign → Import an existing Certificate, pasteclient.crtandclient.key.OPNsense: the same under System → Trust → Authorities and System → Trust → Certificates.
-
Create the OpenVPN client
VPN / OpenVPN / ClientsSaveServer modePeer to Peer (SSL/TLS)ProtocolUDP on IPv4 onlyServer host · portde-fra.realvpn.space · 1194TLS keyUncheckedPeer CA / Client certRealVPN CA / RealVPN clientData ciphersAES-256-GCMOPNsense: VPN → OpenVPN → Instances → +, Role Client, remote
de-fra.realvpn.space:1194, protocol UDP, certificate and CA as above. -
Assign the interface and add NAT
Interfaces → Assignments: add
ovpnc1, enable it (no IP config). Firewall → NAT → Outbound: switch to Hybrid and add a rule for your LAN network on the new interface. To send only some devices through RealVPN, create a LAN firewall rule with the RealVPN gateway.