Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    can not access Open VPN Client lan side networks

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 2 Posters 662 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lalu8364
      last edited by

      Dear All

      I Have Pfsense sever running with open vpn server and i can able to connect from open vpn client to the server and it is working fine.

      my requirement is giving below

      Current setup
      Site A
      Pfsense with open server

      site B
      pfsense with open vpn client connected to the Open vpn server
      Lan Side network is connected with computers

      Site C
      Open vpn client users

      currently i can able to communicate to the site C open vpn client users from site B Lan networks systems

      But i want to communicate to the site B Lan side systems from site C open vpn client users

      Please tell me how to setup to communicate through open vpn client to the lan side network .

      Lalu R.S

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @lalu8364
        last edited by

        @lalu8364
        Do you have only one server and both, site B and C are connecting to it?
        If so you have to configure a client specific override for B. Did you do that?

        L 1 Reply Last reply Reply Quote 0
        • L
          lalu8364 @viragomann
          last edited by

          @viragomann Thank you for your reply

          yes, we have the Pfsense server in site A only and site B and site C is connecting to site A
          No i didn`t, can you please tell me how to configure the specific override for B and where to do that.

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @lalu8364
            last edited by

            @lalu8364
            Best practice is to separate remote access servers and site-to-site servers. But it should also be doable with a single server.

            With a single server you need some specific settings:
            VPN > OpenVPN > Client Specific Overrides
            Assuming your server is running in TLS mode, add a new override. At "Common Name" enter the common name of the site B's client certificate.
            Below at "Tunnel Network" enter an IP out of the tunnel network and the proper mask. This IP will be assigned to B.
            Into the "Remote Network/s" field enter the site B local network in CIDR notation (e.g. 192.168.5.0/24)
            You also have to enter this network as route line into the custom options in the server settings, but here in dotted notation like

            route 192.168.5.0 255.255.255.0
            
            L 1 Reply Last reply Reply Quote 0
            • L
              lalu8364 @viragomann
              last edited by

              @viragomann Thank you for your replay..

              Let me check these setting and update you..

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.