New: VLESS protocol — stays connected where other VPNs get blocked
Features Pricing Server locations Download Help center Extra devices

Account overview My devices Redeem a code Manual VPN setup Change password
Get RealVPN Sign in Redeem a code

pfSense & OPNsense

OpenVPN client instance with certificates.

pfSense · OPNsense OpenVPN 12 min 2 min read

pfSense and OPNsense can route your whole network through RealVPN with an OpenVPN client. The flow: import certificates → create the client → assign an interface → outbound NAT.

What you need

  • pfSense CE 2.6+ / Plus, or OPNsense 23.x+
  1. Get your OpenVPN certificates

    On realvpn.io/settings choose OpenVPN UDP, a location and New manual device, then press Generate config. RealVPN.ovpn is saved to your Downloads.

    Then press Certificates (.zip) and unzip it — you’ll need ca.crt, client.crt, client.key and the server name in server.txt.

    OpenVPN config downloaded on the Manual VPN setup page
  2. Import the CA and the client certificate

    pfSense: System → Cert Manager → CAs → Add → Import an existing Certificate Authority, paste ca.crt. Then Certificates → Add/Sign → Import an existing Certificate, paste client.crt and client.key.

    OPNsense: the same under System → Trust → Authorities and System → Trust → Certificates.

  3. Create the OpenVPN client

    OPNsense: VPN → OpenVPN → Instances → +, Role Client, remote de-fra.realvpn.space:1194, protocol UDP, certificate and CA as above.

  4. Assign the interface and add NAT

    Interfaces → Assignments: add ovpnc1, enable it (no IP config). Firewall → NAT → Outbound: switch to Hybrid and add a rule for your LAN network on the new interface. To send only some devices through RealVPN, create a LAN firewall rule with the RealVPN gateway.