Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WEBGUI access from VPN

    Scheduled Pinned Locked Moved OpenVPN
    8 Posts 2 Posters 974 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      hajdeo
      last edited by

      Hi guys,

      I have successfully launched the VPN client, the connection is active and working.

      9ae29ea1-75ed-4605-825b-dc196e3ecf4f-image.png
      95d22d5d-d0b0-4914-904e-82480cc3cc83-image.png

      Suppose the external VPN address is XXX.XXX.XXX.XXX.XXX and I would need to access the router or WebGui through this address.I already managed to get it to work once, but I had to reset the settings and I can't do it again.

      Do I need to configure somehow the interface, port forward?

      Here si pics of config :
      0a2d821e-71ca-4461-acfc-495cce254bea-image.png

      a8d033ae-92a5-488d-8f37-787745710f86-image.png

      af0a3666-c271-4cea-bc4b-b858f575ab7d-image.png

      thank you!!!

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @hajdeo
        last edited by

        @hajdeo
        Generally you should not allow webGUI access on WAN. But this is, what your Anti-Lockout rule does.
        Note that this setting allows webGUI access without VPN.

        Also your manually added WAN rule allows any TCP traffic to the WAN interface.

        Add a rule to the OpenVPN interface allow access. Then access it by using the OpenVPN server IP.
        Or assign a virtual private IP to WAN (Firewall > virtual IPs) of type "IP alias" and add this in the OpenVPN server settings to the "Local Networks". Then you can use this to access the webGUI. Consider to add a proper rule on the OpenVPN tab.

        H 1 Reply Last reply Reply Quote 0
        • H
          hajdeo @viragomann
          last edited by

          @viragomann Hi, thanks for your time.

          9b89b4f4-fc73-496f-a29a-43acb174b9bb-image.png

          added but nothing happend....any sugestion?

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @hajdeo
            last edited by

            @hajdeo
            You cannot access the WAN address through the VPN. So this rule is pretty useless.
            The WAN address cannot be routed through the VPN, otherwise the VPN wouldn't stay alive.

            I recommended to access the webGUI either by the OpenVPN servers virtual IP or by a manually virtual, which you've to assign to the WAN interface before.
            The OpenVPN servers IP is the first usable IP out of the tunnel network.
            You can also assign an additional virtual IP to the VPN interface, however, you would have to assign an interface to the OpenVPN instance and enable it at before.

            H 1 Reply Last reply Reply Quote 0
            • H
              hajdeo @viragomann
              last edited by

              @viragomann

              hm...can you please provide me step-by-step how add virtual IP?.....if you have a time?

              tahnk you so much!

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @hajdeo
                last edited by

                @hajdeo
                I just noticed, that you're running an OpenVPN client. I was thinking about a server.
                What is the goal of this setup, running a vpn client on a router, which only has a single WAN.
                And obviously this WAN interface has a private IP. So pfSense might be behind another router.

                So you I'm wondering from where you want to access it. From the server network?
                You should be able to access it simply by the clients virtual IP.

                Do you have a CSO on the server for this client? This would be needed to access any other IP that the clients virtual IP from the server side.

                H 1 Reply Last reply Reply Quote 0
                • H
                  hajdeo @viragomann
                  last edited by

                  @viragomann I want to access it from the internet. I don't have a public public IP, this way I can access pfsense webgui directly using the client. I already had it set up this way once, but I had to reset the router and I can't get it set up

                  H 1 Reply Last reply Reply Quote 0
                  • H
                    hajdeo @hajdeo
                    last edited by

                    @hajdeo said in WEBGUI access from VPN:

                    @viragomann I want to access it from the internet. I don't have a public public IP, this way I can access pfsense webgui directly using the client. I already had it set up this way once, but I had to reset the router and I can't get it set up

                    hi frien...is done :) my opsense webgui is accessable from internet, just added this to port forwarding :)
                    e7e5fa37-cc9c-4533-b4b3-ca40006f3bc5-image.png

                    Do you think, is possible add rule to access another LAN IP adress (where is plex) from internt through this VPN connection?

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.