Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Standard OVPN setup question

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 2 Posters 990 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tknospdr @rcoleman-netgate
      last edited by

      @rcoleman-netgate

      That would be checking the box here, right?

      Force all client-generated IPv4 traffic through the tunnel.

      I'll try it but can't test till tomorrow when I get back to work unless you know a trick to test when you're already on the local network.

      R 1 Reply Last reply Reply Quote 0
      • R
        rcoleman-netgate Netgate @tknospdr
        last edited by rcoleman-netgate

        @tknospdr Yep

        You don't want to test a VPN from inside the network. You could tether to a cell phone, though, for testing.

        Ryan
        Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
        Requesting firmware for your Netgate device? https://go.netgate.com
        Switching: Mikrotik, Netgear, Extreme
        Wireless: Aruba, Ubiquiti

        T 1 Reply Last reply Reply Quote 0
        • T
          tknospdr @rcoleman-netgate
          last edited by

          @rcoleman-netgate

          Good call on the cell phone tether.
          Yes, with that option checked I can see everything, I'm guessing I don't really want that option in a perfect world though as it will slow down everything else I do on the Internet.

          R 1 Reply Last reply Reply Quote 0
          • R
            rcoleman-netgate Netgate @tknospdr
            last edited by

            @tknospdr Then what it suggests is you have something in the config (your local IPv4 networks) that is causing trouble compared to your other routes.

            Try tethering again but with the redirect turned off.

            you could have IPv4 network overlaps

            Ryan
            Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
            Requesting firmware for your Netgate device? https://go.netgate.com
            Switching: Mikrotik, Netgear, Extreme
            Wireless: Aruba, Ubiquiti

            T 1 Reply Last reply Reply Quote 0
            • T
              tknospdr @rcoleman-netgate
              last edited by

              @rcoleman-netgate

              I'll try it again tonight when I get home.
              When you say network overlaps, are you talking about subnets?

              What I have configured on the pfS box is 192.168.2.0, 10.100.10.0, 10.100.20.0, and the VPN is using 192.168.3.0.

              R 1 Reply Last reply Reply Quote 0
              • R
                rcoleman-netgate Netgate @tknospdr
                last edited by

                @tknospdr What is the network you're using to get online using for it's range? What is the computer? Windows? Linux? macOS? can you ping through to pfSense (use Diag>Packet Capture to see) if it is clearing the OVPN link and dying on the firewall it's a server-side issue; if it is not routing at all through OVPN its a local client issue. Since doin the "full tunnel" test worked I suspect it's an issue specific to your device you're connecting from. Maybe it has one of those networks manually entered on an interface (static ETH?) or there's an overlapping network locally.

                All of those things can cause issues trying to route traffic over a VPN.

                Ryan
                Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                Requesting firmware for your Netgate device? https://go.netgate.com
                Switching: Mikrotik, Netgear, Extreme
                Wireless: Aruba, Ubiquiti

                T 1 Reply Last reply Reply Quote 0
                • T
                  tknospdr @rcoleman-netgate
                  last edited by

                  @rcoleman-netgate said in Standard OVPN setup question:

                  @tknospdr What is the network you're using to get online using for it's range?

                  192.168.123.0

                  What is the computer? Windows? Linux? macOS?

                  macOS

                  can you ping through to pfSense (use Diag>Packet Capture to see)

                  I assume you mean after I turn off the redirect again, right?

                  if it is clearing the OVPN link and dying on the firewall it's a server-side issue; if it is not routing at all through OVPN its a local client issue.

                  I'll test and report back.

                  Since doin the "full tunnel" test worked I suspect it's an issue specific to your device you're connecting from. Maybe it has one of those networks manually entered on an interface (static ETH?) or there's an overlapping network locally.

                  I don't think so, but I'll keep snooping.

                  All of those things can cause issues trying to route traffic over a VPN.

                  Thanks for the help so far.

                  T 1 Reply Last reply Reply Quote 0
                  • T
                    tknospdr @tknospdr
                    last edited by

                    I found an unused "guest network" on my AP. Nobody is connected to it (wifi is off and no ports on its switch are filled), but its DHCP server was serving out addresses on 192.168.2.0.

                    I turned off DHCP on it and I'm still able to connect and contact other hosts after recinding the redirect.
                    So that may have been what was causing it.
                    I'll see how it goes over the next few days.

                    Thanks for the help!

                    R 1 Reply Last reply Reply Quote 1
                    • R
                      rcoleman-netgate Netgate @tknospdr
                      last edited by

                      @tknospdr You're welcome.

                      Ryan
                      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                      Requesting firmware for your Netgate device? https://go.netgate.com
                      Switching: Mikrotik, Netgear, Extreme
                      Wireless: Aruba, Ubiquiti

                      1 Reply Last reply Reply Quote 0
                      • T
                        tknospdr
                        last edited by

                        I can confirm after several days of work that the VPN has been rock solid and speedy with the 'redirect all traffic' box unchecked since I killed that sneaky DHCP server on my AP.

                        Glad this forum is here!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.