opnSense Road Warrior

  1. Create a Certificate of Authority (hint, use an existing one if you want)
  2. Set up local authentication
  3. Create a Server Certificate (recommend you create a new one)
  4. Server Settings. The default is usually ok, and you can change all but the crypt after creation. Tunnel network and Local Port MUST be unique in all networks concerned.
  5. Firewall Rule Configuration: Allow wizard to make all of them, then go into rules afterwards and look for duplicates.
