Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Beyond Frustrated and Confused..

    Scheduled Pinned Locked Moved OpenVPN
    14 Posts 5 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Cool_CoronaC
      Cool_Corona
      last edited by

      Have you setup the GW for the VPN network?? And created outbound rules??

      godyourestupidG 1 Reply Last reply Reply Quote 0
      • godyourestupidG
        godyourestupid @Cool_Corona
        last edited by

        @cool_corona said in Beyond Frustrated and Confused..:

        Have you setup the GW for the VPN network?? And created outbound rules??

        I assume GW means gateway? If so, I used the gateway settings in the above attached instructions. No luck

        HOWEVER, I did not create outbound rules. I didn't recall seeing anything in there for that.

        KOMK 1 Reply Last reply Reply Quote 0
        • KOMK
          KOM @godyourestupid
          last edited by KOM

          @godyourestupid Why are you using 2.5.0? That's old and not even the latest of the 2.5 branch. There have been changes to OpenVPN since then IIRC so I would strongly suggest you upgrade to 2.6. You need to create a gateway for your OpenVPN config and then create a LAN firewall rule that directs traffic to the VPN gateway. Rule placement order is important. Lastly, an outbound NAT rule so that traffic using the VPN gateway will be NATed to the VPN interface instead of WAN.

          Edit: I just checked that guide and everything is in there so you must have done something wrong. Post screens of your OpenVPN config, your LAN rules, your outbound NAT rules, and maybe we can spot something obvious.

          godyourestupidG 1 Reply Last reply Reply Quote 1
          • P
            pftdm007
            last edited by

            If you haven't created the NAT Outbound rule for each of your local LAN's (VLAN's, etc) then you have not followed the NordVPN tutorial to the letter. Review each step. I just did this on 2.6 and after some fears of having downtime, I must say it worked flawlessly and pretty much right away (thanks to @KOM !)

            1 Reply Last reply Reply Quote 0
            • godyourestupidG
              godyourestupid @KOM
              last edited by

              @kom

              Firewall NAT Outbound.png Firewall Rules LAN.png [NAT Outbound Edit.pdf](Invalid file type. Allowed types are: .png, .jpg, .bmp, .txt, .gif, .xls, .gz, .zip, .pcap, .pcapng, .7z, .xml, .jpeg, .diff, .patch, .tgz, .tar, .0, .cap) OpenVPN Clients Edit_Page_8.png OpenVPN Clients Edit_Page_7.png OpenVPN Clients Edit_Page_6.png OpenVPN Clients Edit_Page_5.png OpenVPN Clients Edit_Page_4.png OpenVPN Clients Edit_Page_3.png OpenVPN Clients Edit_Page_2.png OpenVPN Clients Edit_Page_1.png NAT Outbound Edit_Page_2.png NAT Outbound Edit_Page_1.png

              I hope I included everything you asked for.

              Thank you all for taking the time to look at this!

              Bob.DigB KOMK 2 Replies Last reply Reply Quote 0
              • Bob.DigB
                Bob.Dig LAYER 8 @godyourestupid
                last edited by Bob.Dig

                @godyourestupid What is 192.168.2.0/24? Also better use hybrid outbound.

                godyourestupidG 1 Reply Last reply Reply Quote 0
                • KOMK
                  KOM @godyourestupid
                  last edited by

                  @godyourestupid When you say you can't connect, what do you mean? Can you ping 8.8.8.8? Can you resolve www.google.com (or any external site)?

                  godyourestupidG 1 Reply Last reply Reply Quote 0
                  • godyourestupidG
                    godyourestupid @KOM
                    last edited by

                    @kom said in Beyond Frustrated and Confused..:

                    @godyourestupid When you say you can't connect, what do you mean? Can you ping 8.8.8.8? Can you resolve www.google.com (or any external site)?

                    When I ping, 8.8.8.8 or google.com, I get request timed out.

                    1 Reply Last reply Reply Quote 0
                    • godyourestupidG
                      godyourestupid @Bob.Dig
                      last edited by godyourestupid

                      @bob-dig said in Beyond Frustrated and Confused..:

                      @godyourestupid What is 192.168.2.0/24? Also better use hybrid outbound.

                      192.168.2.0/24 is set from the directions listed by Nord, along with using manual rules for outboud.

                      Aaaaaaand I just changed it from 192.168.2.0 to 192.168.1.0 and it worked. I cannot believe I missed that.

                      Thank you so much! @Bob-Dig and @KOM

                      Bob.DigB 1 Reply Last reply Reply Quote 0
                      • Bob.DigB
                        Bob.Dig LAYER 8 @godyourestupid
                        last edited by

                        @godyourestupid said in Beyond Frustrated and Confused..:

                        192.168.2.0/24 is set from the directions listed by Nord, along with using manual rules for outboud.

                        You havbe to change that to your LAN IP address space.

                        godyourestupidG 1 Reply Last reply Reply Quote 1
                        • godyourestupidG
                          godyourestupid @Bob.Dig
                          last edited by

                          @bob-dig Thank you for all your help!

                          BTW I updated to 2.6 AND I will make a back up of my config once I have everything back up. PFBlocker is next. :)

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.