Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NordVPN and Pfsense with LAN and OPT1 Routing, can't access IoT device with VPN enabled

    Scheduled Pinned Locked Moved Routing and Multi WAN
    11 Posts 2 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      ACE 1
      last edited by ACE 1

      Hello

      I have LAN setup with 10.10.0.1 dhcp configured, OPT1 with 192.168.99.1 dhcp configured. Everything worked great and I could ping everything on both LAN and OPT1 and i could reach any IoT sites or web interface from my main windows computer.

      I then configured NordVPN and everything went well with the setup except for Netflix and a couple of streaming services. So I created VPN Gateway groups to fix and a couple of rules on the LAN firewall to fix this issue.

      Now the the problem is when NordVPN is disabled everything works perfect, but as soon as I enabled it I loose the ability to go to any IoT devices web page on the 192.168.99.1 network.
      Before I could go to any of the 192.168.99.1 network addresses and configure what ever i needed.

      When I ping from my windows computer I get this:
      Screenshot 2022-05-11 134900.png

      10.8.2.1 is the NordVPN Gateway

      1.png

      Am i missing something?

      Do I have to create another NAT Outbound rule for the 192.168.99.0 network.

      Thanks

      Bob.DigB 1 Reply Last reply Reply Quote 0
      • Bob.DigB
        Bob.Dig LAYER 8 @ACE 1
        last edited by

        @ace-1 Show the rules.

        1 Reply Last reply Reply Quote 0
        • A
          ACE 1
          last edited by

          1.png 2.png

          1 Reply Last reply Reply Quote 0
          • A
            ACE 1
            last edited by

            1.png

            Bob.DigB 1 Reply Last reply Reply Quote 0
            • Bob.DigB
              Bob.Dig LAYER 8 @ACE 1
              last edited by Bob.Dig

              @ace-1 Create an RFC1918 Alias for you LAN, it can't work if the nord-gateway (or any other gateway) is first for destination any.
              Or just make a rule LAN to OPT without a gateway on top of LAN.

              1 Reply Last reply Reply Quote 0
              • A
                ACE 1
                last edited by

                Like this?
                3.png

                1 Reply Last reply Reply Quote 0
                • A
                  ACE 1
                  last edited by

                  That works for my IoT devices now but I loose my VPN for 10.10.0.9.

                  Created the second rule you said and it worked, VPN up on 10.10.0.9 plus I can get the IoT device webpage.
                  Your a genius !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

                  Bob.DigB 1 Reply Last reply Reply Quote 0
                  • A
                    ACE 1
                    last edited by

                    g1.png

                    1 Reply Last reply Reply Quote 0
                    • Bob.DigB
                      Bob.Dig LAYER 8 @ACE 1
                      last edited by

                      @ace-1 said in NordVPN and Pfsense with LAN and OPT1 Routing, can't access IoT device with VPN enabled:

                      Your a genius !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

                      Or you have to learn some more of the basics. ๐Ÿ˜‰

                      1 Reply Last reply Reply Quote 0
                      • A
                        ACE 1
                        last edited by

                        Your probably right about that, I still can't get my head around the firewall rules. I am looking in the logs to see what is happening but it seems the basic stuff controls everything.......well I will continue to keep reading.
                        Thanks again for the help

                        Bob.DigB 1 Reply Last reply Reply Quote 0
                        • Bob.DigB
                          Bob.Dig LAYER 8 @ACE 1
                          last edited by Bob.Dig

                          @ace-1 It is easy. ๐Ÿ˜‰

                          Capture.PNG
                          For instance, your rule there has a destination of any (everything) and it has a gateway set, which means, everything has to go through that gateway out to the internet, so no chance for you to connect to IoT anymore.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.