Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Issues with Subnet behind UDM Pro

    Scheduled Pinned Locked Moved OpenVPN
    57 Posts 5 Posters 13.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      viragomann @Misinthe
      last edited by

      @misinthe
      As I mentioned, network devices may probably block access from outside their subnet. That is the default behavior.

      To investigate use the Ping tool on pfSense in the Diagnostic menu to ping a device behind the UDM. Try a ping with default settings, then change the source to OpenVPN and try again.

      ? M 2 Replies Last reply Reply Quote 0
      • ?
        A Former User @viragomann
        last edited by

        @viragomann said in Issues with Subnet behind UDM Pro:

        network devices may probably block access from outside their subnet.

        It is possible, but even so in your firewall rule you have nothing so I understand that this rule is not even running.

        On the other hand @Misinthe shows his openvpn configuration, this would help a lot.

        V M 2 Replies Last reply Reply Quote 0
        • V
          viragomann @A Former User
          last edited by viragomann

          @silence said in Issues with Subnet behind UDM Pro:

          but even so in your firewall rule you have nothing so I understand that this rule is not even running.

          So you say, allowing anything from any to any is not sufficient?
          What are you missing?

          @Misinthe
          BTW: You should modify the block DNS rule on LAN and change the protocol to TCP/UDP. DNS may possibly fallback to TCP.

          ? 1 Reply Last reply Reply Quote 0
          • ?
            A Former User @viragomann
            last edited by

            @viragomann said in Issues with Subnet behind UDM Pro:

            What are you missing?

            320dd2de-5613-46f4-a0a4-60112ae6e0c6-image.png

            I mean these rules all 0 / 0 !

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @A Former User
              last edited by

              @silence
              Ahh, but we talking here about an issue of accessing the network behind the UDM from an OpenVPN client, which is connected to pfSense. So these rules are not relevant here.

              ? 1 Reply Last reply Reply Quote 0
              • ?
                A Former User @viragomann
                last edited by

                @viragomann said in Issues with Subnet behind UDM Pro:

                Ahh, but we talking here about an issue of accessing the network behind the UDM from an OpenVPN client, which is connected to pfSense. So these rules are not relevant here.

                These rules point to ip as 10.20.50.0, it seems to me that they were confused, this must be placed in the configuration of their openvpn.

                M 1 Reply Last reply Reply Quote 0
                • M
                  Misinthe @A Former User
                  last edited by

                  @silence said in Issues with Subnet behind UDM Pro:

                  @viragomann said in Issues with Subnet behind UDM Pro:

                  network devices may probably block access from outside their subnet.

                  It is possible, but even so in your firewall rule you have nothing so I understand that this rule is not even running.

                  On the other hand @Misinthe shows his openvpn configuration, this would help a lot.

                  Thank you, I modified it.

                  ? 1 Reply Last reply Reply Quote 0
                  • M
                    Misinthe @A Former User
                    last edited by

                    @silence said in Issues with Subnet behind UDM Pro:

                    @viragomann said in Issues with Subnet behind UDM Pro:

                    Ahh, but we talking here about an issue of accessing the network behind the UDM from an OpenVPN client, which is connected to pfSense. So these rules are not relevant here.

                    These rules point to ip as 10.20.50.0, it seems to me that they were confused, this must be placed in the configuration of their openvpn.

                    So those rules are not really being used right now because I haven't finished setting my Webhost up.

                    Only the OpenVPN points to 10.20.50.0, which is what I'm trying to make work, the other uses 10.30.0.50, which is a VM's IP on my DMZ host.

                    1 Reply Last reply Reply Quote 0
                    • ?
                      A Former User @Misinthe
                      last edited by

                      @misinthe said in Issues with Subnet behind UDM Pro:

                      Thank you, I modified it.

                      Do not forget to like the comment, which helped you solve your problem. Thank you

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        Misinthe @viragomann
                        last edited by

                        @viragomann

                        So, here are the results.

                        Default to Google
                        89e037c7-21b2-4303-8847-189f682aaf5c-image.png

                        Default to Lan Server
                        85f7aa73-6fbd-4cd5-a0f9-2c59eefafe23-image.png

                        OpenVPN to Google
                        31e03ee6-e82b-4717-8f15-69bf2960ca92-image.png

                        OpenVPN to Lan Server
                        828954aa-305f-49a2-b467-27e2d8054fb8-image.png

                        V 1 Reply Last reply Reply Quote 0
                        • M
                          Misinthe @A Former User
                          last edited by

                          @silence said in Issues with Subnet behind UDM Pro:

                          @misinthe said in Issues with Subnet behind UDM Pro:

                          Thank you, I modified it.

                          Do not forget to like the comment, which helped you solve your problem. Thank you

                          It didn't fix my issue, I just modified the rule in the DNS rule like you suggested.

                          ? 1 Reply Last reply Reply Quote 0
                          • ?
                            A Former User @Misinthe
                            last edited by

                            @misinthe said in Issues with Subnet behind UDM Pro:

                            It didn't fix my issue, I just modified the rule in the DNS rule like you suggested.

                            Excellent, now we can go step by step: this server 10.10.0.5 what is it? and from it you can reach 8.8.8.8 ?

                            ? M 2 Replies Last reply Reply Quote 0
                            • ?
                              A Former User @A Former User
                              last edited by

                              @Misinthe you lan server know how to get back to pfsense?

                              M 1 Reply Last reply Reply Quote 0
                              • M
                                Misinthe @A Former User
                                last edited by

                                @silence said in Issues with Subnet behind UDM Pro:

                                @misinthe said in Issues with Subnet behind UDM Pro:

                                It didn't fix my issue, I just modified the rule in the DNS rule like you suggested.

                                Excellent, now we can go step by step: this server 10.10.0.5 what is it? and from it you can reach 8.8.8.8 ?

                                This is my media server, Emby/Plex. And yes, everything on my 10.10.0.0/24 network can reach out to the internet, that's my home's main LAN.

                                1 Reply Last reply Reply Quote 0
                                • M
                                  Misinthe @A Former User
                                  last edited by Misinthe

                                  @silence said in Issues with Subnet behind UDM Pro:

                                  @Misinthe you lan server know how to get back to pfsense?

                                  What do you mean? All my networks use PfSense as DNS server, so pfBlockerNG can do it's thing.

                                  I'm starting to believe the UDMP might be the one blocking.

                                  ? 1 Reply Last reply Reply Quote 0
                                  • ?
                                    A Former User @Misinthe
                                    last edited by

                                    @misinthe publish your openvpn configuration.

                                    M 1 Reply Last reply Reply Quote 0
                                    • M
                                      Misinthe @A Former User
                                      last edited by

                                      @silence said in Issues with Subnet behind UDM Pro:

                                      @misinthe publish your openvpn configuration.

                                      Here you go

                                      4634800b-665f-42a1-b03d-b0185a24ac02-image.png

                                      c1b42f11-1242-4cb1-bae7-fc8d2979126e-image.png

                                      ee965190-3185-4ed4-a679-ea63e41ab863-image.png

                                      a7237966-8a9e-4aef-9ff4-9af9ce3ce947-image.png

                                      52ca60a1-ae59-4f83-95ef-b28f1ee4798f-image.png

                                      b500169a-1ab0-4b5f-8d5e-5d50e8c4c259-image.png

                                      0304202c-325c-4627-8e86-1fe3a9512c73-image.png

                                      1 Reply Last reply Reply Quote 0
                                      • V
                                        viragomann @Misinthe
                                        last edited by

                                        @misinthe said in Issues with Subnet behind UDM Pro:

                                        So, here are the results.

                                        So as you see, you don't get a respond from the server, even if the static route points to the UDM.

                                        So next step is to sniff the traffic on the UDM on both WAN and LAN side, while you send pings from pfSense. Or maybe you can sniff the packets on the destination server itself.

                                        Remember what I said about the operating system firewall beginning with my first here.

                                        M 1 Reply Last reply Reply Quote 0
                                        • M
                                          Misinthe @viragomann
                                          last edited by

                                          @viragomann said in Issues with Subnet behind UDM Pro:

                                          @misinthe said in Issues with Subnet behind UDM Pro:

                                          So, here are the results.

                                          So as you see, you don't get a respond from the server, even if the static route points to the UDM.

                                          So next step is to sniff the traffic on the UDM on both WAN and LAN side, while you send pings from pfSense. Or maybe you can sniff the packets on the destination server itself.

                                          Remember what I said about the operating system firewall beginning with my first here.

                                          I feel it's more the UDM blocking because I can't reach anything behind it, not just my media server.

                                          ? 1 Reply Last reply Reply Quote 0
                                          • ?
                                            A Former User @Misinthe
                                            last edited by A Former User

                                            @misinthe said in Issues with Subnet behind UDM Pro:

                                            not just my media server.

                                            MARK THIS OPTION PLEASE

                                            9a8918f7-adf5-4b67-84c8-f07880905cb9-image.png

                                            Because it repeats 10.20.50.0/24 ?

                                            31479cd4-f6bf-4a9b-aabb-e85450a410dc-image.png

                                            M 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.