Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsesne 2.7.0 OpenVPN Client connected, RDP Work OK BUT no internet access

    Scheduled Pinned Locked Moved OpenVPN
    34 Posts 4 Posters 3.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      viragomann @Unoptanio
      last edited by

      @Unoptanio
      So you provide public DNS servers. However, this has nothing to do with the DNS settings in pfSense. You could also provide any other server in the VPN.

      Normally the client pulls these settings and use the stated DNS servers, when the connection is established.
      If you don't route them over the VPN, the client should access the DNS servers over its own upstream connection.
      So I assume, there is an issue on the client side. Maybe the clients log give hints about the problem.

      UnoptanioU 2 Replies Last reply Reply Quote 0
      • UnoptanioU
        Unoptanio @viragomann
        last edited by Unoptanio

        @viragomann

        https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-s2s-route-internet-traffic.html

        I'm reading this article but I don't understand how to fix my problem.

        It seems to me that once you connect to the VPN there are two possibilities to use the internet:

        1. use the local internet connection of the client PC

        2. use the internet connection of the remote tunnel VPN server

        I use VPN to use RemoteDesktop safely. But I would also like to use the browser on my client pc using the connection of the local client pc or possibly with that of the remote server via the vpn tunnel.

        Currently every time I want to use the browser and email I have to disconnect from the vpn

        I made this setting.
        But it doesn't solve the problem:

        4d4da5b0-ad19-4a53-a608-c02d32f668b9-image.png

        pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
        CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
        n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

        1 Reply Last reply Reply Quote 0
        • UnoptanioU
          Unoptanio
          last edited by Unoptanio

          RESOLVED!!!!!!😂

          I've gone crazy.

          Enabling this item now works. I can access the internet (browser, email, etc) on the remote client pc while they are also connected in VPN with Remote Desktop

          e82a37f6-9a5c-4253-b922-ce53bf95296a-image.png

          8e06b290-46fe-47f5-b426-798a8c1b2bb0-image.png

          pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
          CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
          n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

          1 Reply Last reply Reply Quote 0
          • UnoptanioU
            Unoptanio @viragomann
            last edited by Unoptanio

            @viragomann

            Tested by checking the public ip.
            On the remote client pc, the internet goes out with the local connection of the pc and not with that of the remote OpenVpn tunnel.

            Do you know if it is possible to get it out with the remote VPN tunnel connection?

            IPCONFIG in client pc:
            dfbd8fff-2b98-4aae-88f9-4a135dd3bc13-image.png

            bba73811-df44-476e-a638-937a1501461d-image.png

            pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
            CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
            n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @Unoptanio
              last edited by

              @Unoptanio
              Go into the OpenVPN server settings and add a check at "Redirect gateway".

              However, this also needs an outbound NAT rule on WAN for the source of the tunnel network. If you went through the wirzard, pfSense might have add it automatically, otherwise set outbound NAT back to hybrid mode and add the rule manually as you had it before.

              UnoptanioU 1 Reply Last reply Reply Quote 1
              • UnoptanioU
                Unoptanio @viragomann
                last edited by

                @viragomann
                5a8d4c97-41ef-430c-bcf7-5daaa49d60a2-image.png

                pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                UnoptanioU 1 Reply Last reply Reply Quote 0
                • UnoptanioU
                  Unoptanio @Unoptanio
                  last edited by

                  @Unoptanio

                  if i check redirect ipv4 gateway then disappear ipv4 local network

                  21b0f243-07e2-4205-80bc-dc7f1ba8ccaf-image.png

                  pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                  CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                  n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                  V 1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @Unoptanio
                    last edited by

                    @Unoptanio said in Pfsesne 2.7.0 OpenVPN Client connected, RDP Work OK BUT no internet access:

                    if i check redirect ipv4 gateway then disappear ipv4 local network

                    Yes, this is not needed anymore in this case.
                    It pushes the route for the local networks to the clients. Redirect gateway pushes the default route, i.e. any traffic is routed over the VPN.

                    UnoptanioU 1 Reply Last reply Reply Quote 1
                    • UnoptanioU
                      Unoptanio @viragomann
                      last edited by Unoptanio

                      @viragomann

                      df02aac7-56ba-424e-bf89-b2da67ee918c-image.png

                      great thanks it works. Tested now.
                      with this change the internet use the remote tunnel

                      pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                      CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                      n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                      UnoptanioU 1 Reply Last reply Reply Quote 0
                      • UnoptanioU
                        Unoptanio @Unoptanio
                        last edited by

                        @Unoptanio

                        The crucial setting that didn't make the internet work on the local pc but only the VPN was this

                        a2229232-0575-427c-b831-cabd9dc47d21-image.png

                        pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                        CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                        n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                        UnoptanioU 1 Reply Last reply Reply Quote 0
                        • UnoptanioU
                          Unoptanio @Unoptanio
                          last edited by Unoptanio

                          @Unoptanio

                          Performance:

                          Test speed under remote server openvpn on firewall pfsense: (1Gb optical fiber)
                          c212538d-922a-4a4c-a908-297e24ab4a3a-image.png

                          Test speed in remote pc client with OPEN VPN ON with internet routed on the remote server .......shouldn't it go faster?
                          23643115-d335-4910-a504-1d0e2d57d2f1-image.png

                          Test speed in remote pc client with OPEN VPN OFF with internet on local PC
                          e9910821-fdb2-4c0c-9278-bdb1f9c90e8c-image.png

                          pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                          CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                          n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                          GertjanG 1 Reply Last reply Reply Quote 0
                          • GertjanG
                            Gertjan @Unoptanio
                            last edited by Gertjan

                            @Unoptanio

                            I propose : replace these :

                            133e0183-b761-4060-8d88-6d000b7c74c3-image.png

                            with

                            1129f442-860c-46ba-ba0b-957df23b6520-image.png

                            where 192.168.3.1 is your tunnel IP, 10.10.94.1

                            If you unbound settings are default, you're good :

                            4b5b9404-f6e9-416f-af6e-f71e37e7e89d-image.png

                            (All includes my OpenVPN server called SVPN)

                            as unbound also listens on 10.10.94.1, the OpenVPN server IP on the pfSense side.

                            Why ? Now you can use local URL/host names like server.XXXXpfSense.homa.arpa to join a RDP session on "server" on your LAN.
                            8.8.8.8 and others don't know anything about your local devices ;)

                            No "help me" PM's please. Use the forum, the community will thank you.
                            Edit : and where are the logs ??

                            UnoptanioU 2 Replies Last reply Reply Quote 1
                            • UnoptanioU
                              Unoptanio @Gertjan
                              last edited by Unoptanio

                              @Gertjan

                              HI,
                              that's what I've been trying to do for the last few hours. but at the moment I haven't succeeded yet.
                              I would like to use the computer name in RDP sessions instead
                              of the IP address

                              RDP session using PC NAME not work.
                              fda8aaac-4287-4672-8b01-0e053d475efe-image.png

                              RDP session using ip address of PC work OK.
                              a74d5a3f-1acd-4575-92d7-d621931782e4-image.png

                              765b7893-2a07-4671-b78b-38e031a5d497-image.png

                              i changed the pfsense config like you saids:

                              9077cafa-f740-4a8e-b7a0-f1bae3e189b4-image.png
                              e7957a13-cd73-4a73-a8cb-24579e434d95-image.png

                              pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                              CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                              n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                              UnoptanioU 1 Reply Last reply Reply Quote 0
                              • UnoptanioU
                                Unoptanio @Unoptanio
                                last edited by Unoptanio

                                @Gertjan

                                I find this in "services", "DNS RESOLVER?"

                                e0694b42-e287-471f-9b40-4a41a2b81fb8-image.png

                                I have not added the OPENVPN server in the interfaces.

                                and consequently does not appear in the DNS resolver list.

                                05e1edaf-35c6-4858-995d-2f752ecb7507-image.png

                                pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                                CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                                n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                                S 1 Reply Last reply Reply Quote 0
                                • S
                                  slu @Unoptanio
                                  last edited by

                                  @Unoptanio
                                  dou you have set firewall rules for the OpenVPN connection?

                                  pfSense Gold subscription

                                  UnoptanioU 1 Reply Last reply Reply Quote 0
                                  • UnoptanioU
                                    Unoptanio @slu
                                    last edited by

                                    @slu
                                    the openvpn wizard entered them automatically

                                    d3e5c548-273d-4a9a-8160-aecbcfc78dcd-image.png

                                    pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                                    CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                                    n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                                    S GertjanG 2 Replies Last reply Reply Quote 0
                                    • S
                                      slu @Unoptanio
                                      last edited by

                                      @Unoptanio said in Pfsesne 2.7.0 OpenVPN Client connected, RDP Work OK BUT no internet access:

                                      the openvpn wizard entered them automatically

                                      no I mean internet access from your VPN client over the VPN into WAN.
                                      That was your question, or?

                                      pfSense Gold subscription

                                      1 Reply Last reply Reply Quote 0
                                      • GertjanG
                                        Gertjan @Unoptanio
                                        last edited by Gertjan

                                        @Unoptanio

                                        Observe :

                                        5494765c-9743-4e46-b0cf-777c1394c1f5-image.png

                                        As soon as you connect, the right number will raise.
                                        The left number will show the number of open states, so bigger then 0.

                                        This means traffic comes in ....
                                        Do you see the same ?
                                        To hit your perfect OpenVPN server Firewall rules :

                                        fb5b9d2c-13e4-4de0-a515-f8d8bd4c6f54-image.png

                                        as these are all pass rules (for me : IPv4 and Ipv6) traffic can get everywhere.
                                        Take note : the counter in front of the rules : do they go up ?

                                        If you were connecting to some device on LAN, then the traffic would get routed out to the LAN interface, and then it really try to reach that device ....
                                        Suspense : will this device (its firewall ?) accept this traffic 😊

                                        You can do a packet capturing on the LAN interface, as you know the destination IP, and destination port, and protocol used (UDP ?)
                                        Do you see it ?

                                        No "help me" PM's please. Use the forum, the community will thank you.
                                        Edit : and where are the logs ??

                                        UnoptanioU 1 Reply Last reply Reply Quote 0
                                        • UnoptanioU
                                          Unoptanio @Gertjan
                                          last edited by Unoptanio

                                          @Gertjan

                                          latest updates and tests:
                                          I added a specific OPEN_VPN interface that I didn't have before

                                          89e6c5cc-0483-4b81-85f8-f92dab25a92c-image.png

                                          b77392ad-0b11-449b-8f7a-9828ba611795-image.png
                                          here the numbers turn, there is traffic when there are rdp sessions

                                          4ce21996-5d12-4d0a-9178-83753073d443-image.png

                                          9df11b0b-f865-41be-beaa-9c4724498261-image.png

                                          7248e85b-5f20-49b5-a1f2-aebc9f1f4258-image.png

                                          5d36af37-8b3d-4efb-be23-262c84068843-image.png

                                          08e7131d-d083-49aa-a229-2e2e8e48da08-image.png

                                          The problem:
                                          RDP work only with IP address of the pc
                                          if i use PC name not working

                                          240ff862-52c5-4ead-9422-ff7b68b2d19e-image.png

                                          a0743670-277f-4f52-8353-ac42b4351e51-image.png

                                          7b27e516-b49c-4ab7-b2d5-960e480a9cd1-image.png

                                          pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                                          CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                                          n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                                          GertjanG 1 Reply Last reply Reply Quote 0
                                          • GertjanG
                                            Gertjan @Unoptanio
                                            last edited by Gertjan

                                            @Unoptanio said in Pfsesne 2.7.0 OpenVPN Client connected, RDP Work OK BUT no internet access:

                                            I added a specific OPEN_VPN interface that I didn't have before

                                            9719e739-5b0f-4a93-9835-18c56b397cb0-image.png

                                            This Open_VPN is assigned to the OpenVPN server instance ?

                                            Like this (my OpenVPN server ) :

                                            e0810a06-6255-4422-b3b1-dd5e0093d378-image.png

                                            ?

                                            Then you have probably an issue.
                                            RDP is mostly, if not all, UDP based. Your firewall rule only permits IPv4-TCP and blocks IPv4-UDP.

                                            As proposed : time to do some : Diagnostics > Packet Capture

                                            Btw : read also : Cannot connect with RDP via openVPN for some out of the box thinking ;)

                                            No "help me" PM's please. Use the forum, the community will thank you.
                                            Edit : and where are the logs ??

                                            UnoptanioU 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.