Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN -> LAN (OK) | LAN -> VPN (OFF) need both working

    Scheduled Pinned Locked Moved General pfSense Questions
    53 Posts 2 Posters 3.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      OK so no ICMP packets at all there. But those were all inside 0.2 seconds so maybe it wasn't running long enough?

      What IP address on LAN were you pinging from?

      What we can see there though is that OpenVPN clients are able to connect to hosts on the LAN and they are able to reply. And importantly that there is no NAT. The OpenVPN tunnel IPs appear directly on the LAN.

      B 2 Replies Last reply Reply Quote 0
      • B
        BRQ_michael @stephenw10
        last edited by

        @stephenw10 This test I showed you is from the packet capture of PFSENSE itself for the IP that my clientOPENVPN is getting 50.50.50.2

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          So you didn't try to ping from LAN host?

          Repeat the capture but try to ping from a host on the LAN.

          Pings from pfSense itself never go through the LAN interface to reach the VPN so would not appear in the pcap.

          1 Reply Last reply Reply Quote 0
          • B
            BRQ_michael @stephenw10
            last edited by

            @stephenw10 It's in Portuguese, but it causes 100% packet loss

            55d6eeeb-c8ce-4628-a46a-6c5a8b146c4a-image.png

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Ok and what does the packet capture show on LAN whilst that is running?

              What IP address in the LAN are you pinging from?

              What is 50.50.50.2 there? Another client device?

              By the way 50.50.50.0/24 is a public subnet belonging to Frontier Communications. You should really use a private subnet for the tunnel.

              Steve

              B 1 Reply Last reply Reply Quote 0
              • B
                BRQ_michael @stephenw10
                last edited by

                @stephenw10 But packet capture where? in pfsense? You told me to use ping elsewhere, I don't understand
                50.50.50.2 is another client device that
                50.50.50.0/24 But the tunnel already uses a private subnet, doesn't it?

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  You are saying that you need to be able to connect to OpenVPN clients from hosts in the LAN subnet and it is not working.

                  We are trying to find out why it's failing.

                  So to test that we are trying send ping traffic from a host in the LAN to a VPN client and then looking to see where it goes.

                  The first place it should hit is the pfSense LAN interface.

                  So the test is to start a packet capture on the pfSense LAN interface. Then run the ping and make sure it arrives there.

                  If it doesn't arrive then the issue is on the LAN host.

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    50.50.50.0/24 is a public subnet that should not be used here. BUT that is not the cause of the problem. It only means you could not connect to that subnet if you ever had to which is very unlikely.

                    B 1 Reply Last reply Reply Quote 0
                    • B
                      BRQ_michael @stephenw10
                      last edited by

                      @stephenw10 I pinged directly from my machine to an OPENVPN client and captured the packets from my PFSENSE LAN interface, with these settings:65047155-16ef-422c-ae2d-3f102cc0885d-image.png

                      Try ping 50.50.50.2:7a46ea67-b807-4ac1-9c21-0b97380515bc-image.png

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Ok great. So the ping packets are arriving in the correct place. The client is not responding so either it can't respond (it's blocking them) or it never sees the pings.

                        Next try running the packet capture on the openvpn interface to make sure the pings are leaving the correct way.

                        You can also check the state table while that ping is running so make sure pfSense is open states on the correct interfaces.

                        Can I assume that if you ping the other way, from 50.50.50.2 to 192.168.140.57, it works?

                        B 1 Reply Last reply Reply Quote 0
                        • B
                          BRQ_michael @stephenw10
                          last edited by

                          @stephenw10

                          If I am capturing ICMP packets from my OpenVPN Server interface, the same log that I sent you appears.

                          Yes, if I try to ping ip 50.50.50.2 to 192.168.140.57 it works normally

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            Ok if you see the pings leaving the OpenVPN interface the packets are almost certainly being blocked at the VPN client. A local software firewall on 50.50.50.2.

                            B 1 Reply Last reply Reply Quote 0
                            • B
                              BRQ_michael @stephenw10
                              last edited by

                              @stephenw10 But what could this be blocking? my rules allow everything
                              11ea3a3b-a608-4b5c-aaa0-7f9f5e132a8f-image.png

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                Its almost certainly blocked on the client device directly. So like Windows firewall, if it's a Windows device.

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.