Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ping fails to remote vpn host

    Scheduled Pinned Locked Moved OpenVPN
    3 Posts 2 Posters 347 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      Dman_runner
      last edited by

      on pfsense, if I ping a host behind firewall from a remote vpn host, it works. but if I ping from internal host behind firewall to a remote vpn host, I don't see packets going to openvpn interface on pfsense. do you know what could be the reason ?

      10.0.254.1 ( internal host ) --- NAT --- 192.168.30.1 ( LAG Interface ) -- WAN (OPENVPN 10.0.200.1 ) -- VPN host ( 10.0.200.2)

      so ping works from 10.0.200.2 to 10.0.254.1 ( and I can see packets on tunnel interface in pfsense packet captures )

      ping doesn't work from 10.0.254.1 to 10.0.200.2 ( can't see any icmp packets on packet capture on pfsense tunnel interface )

      However, ping from 10.0.254.1 to 10.0.200.1 works ( I can see packets on packet capture on pfsense tunnel interface )

      Any suggestions how to make this work ?

      thanks

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @Dman_runner
        last edited by

        @Dman_runner said in ping fails to remote vpn host:

        ping doesn't work from 10.0.254.1 to 10.0.200.2 ( can't see any icmp packets on packet capture on pfsense tunnel interface )

        I would expect, that the remote host will block this, since the source is outside of its local subnet. But I'd also expect to see request packets going into the tunnel.

        D 1 Reply Last reply Reply Quote 0
        • D
          Dman_runner @viragomann
          last edited by

          @viragomann It works now. I had to add another firewall rule on the LAG side.

          thanks for your response

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.