Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN clients loosing Internet access

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 3 Posters 595 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      dansci
      last edited by

      Hi, I have a problem with configuring rules for OpenVPN.
      With rules like the following, I have access to local resources and to the Internet when connecting via VPN. But when I disable the first rule allowing everything I lose Internet access on VPN clients. Access to local resources remains for them.

      The rules below the first one are copied from the VLAN, which in my case has practically the same permissions as the VPN clients should have. Only that I have the subnet 192.168.11.0/24 set as the source here, because that's where the clients get their addresses from.

      I am asking for help please.

      6e11f75c-1b83-413f-8c5f-698caef64a04-obraz.png

      V 1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann @dansci
        last edited by

        @dansci
        You have to decide if you want to route the whole clients upstream traffic over the VPN or only your local networks.

        If the local networks only uncheck "Redirect gateway" in the server settings and enter your local networks into the respective box.

        If the clients routes all upstream traffic to the VPN server anyway there must be something wrong with the client VPN.

        D 1 Reply Last reply Reply Quote 0
        • D Offline
          dansci @viragomann
          last edited by

          @viragomann I just need to give clients the ability to access selected local network resources.

          So I set it up as below, now the problem of accessing DNS Resolver on pfSense remains.

          f0188543-688f-40db-8330-8a9be526a0bd-obraz.png

          In the DNS server settings, I see that there is no option to set it on the OpenVPN interface. Hence, VPN clients could use DNS on the main interface: 192.168.99.1. But something is not working for me.
          9561f45f-eb29-4d75-9f5c-cc579a2061a8-obraz.png

          J V 2 Replies Last reply Reply Quote 0
          • J Offline
            Jarhead @dansci
            last edited by Jarhead

            @dansci Just to add, putting an allow all rule on top negates everything below it. First rule that fits is the only one applied.

            D 1 Reply Last reply Reply Quote 0
            • D Offline
              dansci @Jarhead
              last edited by

              @jarhead Thanks, that's what I'm aware of. It was a rule added by the OpenVPN wizard and I keep it there as 'disabled'. I only run it when something completely doesn't want to work, to see if it's a firewall issue.

              1 Reply Last reply Reply Quote 0
              • V Offline
                viragomann @dansci
                last edited by

                @dansci
                Ensure that the OpenVPN tunnel network is added to the Resolvers ACL or add it manually if it isn't.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.