Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Standard OVPN setup question

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 2 Posters 988 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rcoleman-netgate Netgate @tknospdr
      last edited by

      @tknospdr said in Standard OVPN setup question:

      When I connected from outside the network this morning with the official OVPN client it connected almost instantly and stayed connected all day; however, I was not able to see, browse, ping, or remote into ANY clients on my home network.

      Does it work when you tell it to push all your IPv4 traffic through the OVPN connection?

      Ryan
      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
      Requesting firmware for your Netgate device? https://go.netgate.com
      Switching: Mikrotik, Netgear, Extreme
      Wireless: Aruba, Ubiquiti

      T 1 Reply Last reply Reply Quote 0
      • T
        tknospdr @rcoleman-netgate
        last edited by

        @rcoleman-netgate

        That would be checking the box here, right?

        Force all client-generated IPv4 traffic through the tunnel.

        I'll try it but can't test till tomorrow when I get back to work unless you know a trick to test when you're already on the local network.

        R 1 Reply Last reply Reply Quote 0
        • R
          rcoleman-netgate Netgate @tknospdr
          last edited by rcoleman-netgate

          @tknospdr Yep

          You don't want to test a VPN from inside the network. You could tether to a cell phone, though, for testing.

          Ryan
          Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
          Requesting firmware for your Netgate device? https://go.netgate.com
          Switching: Mikrotik, Netgear, Extreme
          Wireless: Aruba, Ubiquiti

          T 1 Reply Last reply Reply Quote 0
          • T
            tknospdr @rcoleman-netgate
            last edited by

            @rcoleman-netgate

            Good call on the cell phone tether.
            Yes, with that option checked I can see everything, I'm guessing I don't really want that option in a perfect world though as it will slow down everything else I do on the Internet.

            R 1 Reply Last reply Reply Quote 0
            • R
              rcoleman-netgate Netgate @tknospdr
              last edited by

              @tknospdr Then what it suggests is you have something in the config (your local IPv4 networks) that is causing trouble compared to your other routes.

              Try tethering again but with the redirect turned off.

              you could have IPv4 network overlaps

              Ryan
              Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
              Requesting firmware for your Netgate device? https://go.netgate.com
              Switching: Mikrotik, Netgear, Extreme
              Wireless: Aruba, Ubiquiti

              T 1 Reply Last reply Reply Quote 0
              • T
                tknospdr @rcoleman-netgate
                last edited by

                @rcoleman-netgate

                I'll try it again tonight when I get home.
                When you say network overlaps, are you talking about subnets?

                What I have configured on the pfS box is 192.168.2.0, 10.100.10.0, 10.100.20.0, and the VPN is using 192.168.3.0.

                R 1 Reply Last reply Reply Quote 0
                • R
                  rcoleman-netgate Netgate @tknospdr
                  last edited by

                  @tknospdr What is the network you're using to get online using for it's range? What is the computer? Windows? Linux? macOS? can you ping through to pfSense (use Diag>Packet Capture to see) if it is clearing the OVPN link and dying on the firewall it's a server-side issue; if it is not routing at all through OVPN its a local client issue. Since doin the "full tunnel" test worked I suspect it's an issue specific to your device you're connecting from. Maybe it has one of those networks manually entered on an interface (static ETH?) or there's an overlapping network locally.

                  All of those things can cause issues trying to route traffic over a VPN.

                  Ryan
                  Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                  Requesting firmware for your Netgate device? https://go.netgate.com
                  Switching: Mikrotik, Netgear, Extreme
                  Wireless: Aruba, Ubiquiti

                  T 1 Reply Last reply Reply Quote 0
                  • T
                    tknospdr @rcoleman-netgate
                    last edited by

                    @rcoleman-netgate said in Standard OVPN setup question:

                    @tknospdr What is the network you're using to get online using for it's range?

                    192.168.123.0

                    What is the computer? Windows? Linux? macOS?

                    macOS

                    can you ping through to pfSense (use Diag>Packet Capture to see)

                    I assume you mean after I turn off the redirect again, right?

                    if it is clearing the OVPN link and dying on the firewall it's a server-side issue; if it is not routing at all through OVPN its a local client issue.

                    I'll test and report back.

                    Since doin the "full tunnel" test worked I suspect it's an issue specific to your device you're connecting from. Maybe it has one of those networks manually entered on an interface (static ETH?) or there's an overlapping network locally.

                    I don't think so, but I'll keep snooping.

                    All of those things can cause issues trying to route traffic over a VPN.

                    Thanks for the help so far.

                    T 1 Reply Last reply Reply Quote 0
                    • T
                      tknospdr @tknospdr
                      last edited by

                      I found an unused "guest network" on my AP. Nobody is connected to it (wifi is off and no ports on its switch are filled), but its DHCP server was serving out addresses on 192.168.2.0.

                      I turned off DHCP on it and I'm still able to connect and contact other hosts after recinding the redirect.
                      So that may have been what was causing it.
                      I'll see how it goes over the next few days.

                      Thanks for the help!

                      R 1 Reply Last reply Reply Quote 1
                      • R
                        rcoleman-netgate Netgate @tknospdr
                        last edited by

                        @tknospdr You're welcome.

                        Ryan
                        Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                        Requesting firmware for your Netgate device? https://go.netgate.com
                        Switching: Mikrotik, Netgear, Extreme
                        Wireless: Aruba, Ubiquiti

                        1 Reply Last reply Reply Quote 0
                        • T
                          tknospdr
                          last edited by

                          I can confirm after several days of work that the VPN has been rock solid and speedy with the 'redirect all traffic' box unchecked since I killed that sneaky DHCP server on my AP.

                          Glad this forum is here!

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.