Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Having trouble accessing NAS through VPN server

    Scheduled Pinned Locked Moved OpenVPN
    25 Posts 5 Posters 447 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      azdeltawye @the other
      last edited by

      @the-other
      I’m on travel for the week so I’ll post the firewall rules when I get home.

      As for my internet, I have Comcast Xfinity with a publicly routeable address. Comcast offers ipv6 support but I only have ipv4 enabled. I use a DDNS service for remote access because my IP changes from time to time..
      I cannot ping my IP when I am remote. I don’t recall if I have a ICMP block rule on my WAN. I’ll check that as well when I get home.

      Thanks for the suggestions.

      the otherT 1 Reply Last reply Reply Quote 0
      • A Offline
        azdeltawye @pwood999
        last edited by

        @pwood999
        No static routes are in place, just the default settings in pfsense.

        1 Reply Last reply Reply Quote 0
        • the otherT Offline
          the other @azdeltawye
          last edited by

          @azdeltawye yeah, but can you ping your dyndns address? That should also give you your actual public IP...can you ping that one?

          the other

          pure amateur home user, no business or professional background
          please excuse poor english skills and typpoz :)

          A 1 Reply Last reply Reply Quote 0
          • A Offline
            azdeltawye @the other
            last edited by

            @the-other
            No, I cannot ping my ddns url. It resolves my WAN IP but times out on the ping attempt.

            S 1 Reply Last reply Reply Quote 0
            • S Offline
              SteveITS Galactic Empire @azdeltawye
              last edited by

              @azdeltawye do you have a firewall rule on WAN allowing ICMP?

              Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
              Upvote 👍 helpful posts!

              A 2 Replies Last reply Reply Quote 0
              • A Offline
                azdeltawye @SteveITS
                last edited by azdeltawye

                @SteveITS
                I do not have a rule to pass ICMP traffic in the WAN interface.

                I’ll have to wait until I get home before I add a rule. Editing firewall rules via remote iPhone connection is sketchy at best…

                1 Reply Last reply Reply Quote 0
                • A Offline
                  azdeltawye @SteveITS
                  last edited by azdeltawye

                  @SteveITS
                  OK, added an Echo Request rule on the WAN to allow ICMP traffic. I can now ping my IP directly and the DDNS URL. However, I still cannot access the NAS with File Explorer.

                  Here are my WAN pass rules:
                  65cbb4aa-a23a-4014-8d0d-76065b86d987-image.png

                  1 Reply Last reply Reply Quote 0
                  • A Offline
                    azdeltawye @the other
                    last edited by azdeltawye

                    @the-other
                    Here are all the active OpenVPN interface rules:
                    ff7983f8-8553-4f2f-a978-078412e0b475-image.png
                    The VPN Servers Alias is this:
                    4f0ab459-827e-4fe2-86f9-8a9afec24c39-image.png

                    GertjanG 1 Reply Last reply Reply Quote 0
                    • GertjanG Offline
                      Gertjan @azdeltawye
                      last edited by Gertjan

                      @azdeltawye

                      What is your pfSense LAN IP, and network ?
                      Like 192.168.1.1 and 255.255.255.0 or /24 ?

                      Your NAS IP, network, gateway and DNS ?
                      Like 192.168.1.x, 255.255.255.0/24 or /24, 192.168.1.1 (gateway !) and 192.168.1.1 (DNS) ?

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      A 1 Reply Last reply Reply Quote 0
                      • A Offline
                        azdeltawye @Gertjan
                        last edited by azdeltawye

                        @Gertjan
                        My pfSense IP is 192.168.125.1 on a /24 network
                        My NAS IP is 192.168.200.4 on a /24 network, the GW and DNS are 192.168.200.1
                        My OpenVPN server tunnel networks are 10.0.10.0/24 & 10.0.20.0/24

                        Like I mentioned in the first post in this thread, this used to work. I think it was around 2 years ago, I could access my NAS via the File Explorer app on my iPhone while logged into my OpenVPN server over a remote connection. So I'm not sure exactly when it broke. Since then, there have been several iOS updates, FE app updates, DSM updates and OpenVPN updates. My pfSense configuration, for the most part, has not changed.

                        BTW, I disabled the allow ping rule on my WAN after getting spammed by ping bots...

                        GertjanG 1 Reply Last reply Reply Quote 0
                        • GertjanG Offline
                          Gertjan @azdeltawye
                          last edited by

                          @azdeltawye

                          Your NAS will send reply traffic to its gateway : 192.168.200.1
                          Or, it local network segment gataway is 192.168.125.1/24
                          Afaik, this can't work.

                          See it like this : traffic arrives from the "10.0.10.0/24 or 10.0.20.0/24" network and s to go the the 192.168.125.1/24 network to reach the NAS.
                          Only 192.168.200.0/24 is known to pfSense .... that's like the post office receiving a letter mentioning a road that doesn't exist in its city.

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          A 1 Reply Last reply Reply Quote 0
                          • A Offline
                            azdeltawye @Gertjan
                            last edited by azdeltawye

                            @Gertjan
                            I hear what you're saying but I don't think that is correct in this situation. I thought PfSense automatically adds VLAN subnets to its routing table when the VLANs are created. And since I have the 'allow all' rule on my VPN server interface, I can ping and access all my VLAN gateways, including the 200 VLAN gateway which is where the NAS lives, when I tunnel into my VPN server.

                            Anecdotally, I have a security camera NVR on my 175 VLAN (192.168.175.0/24) which I have no problem accessing when I tunnel into my VPN server from a remote location. No special entries in the routing table to allow this connection, it just works.

                            And like I mentioned before, this did actually work some years ago. I was able to access the NAS with the FE application from my iOS device over the VPN. Something changed, other than my pfSense configuration that is preventing access now...

                            GertjanG 1 Reply Last reply Reply Quote 0
                            • GertjanG Offline
                              Gertjan @azdeltawye
                              last edited by

                              @azdeltawye said in Having trouble accessing NAS through VPN server:

                              I thought PfSense automatically adds VLAN subnets

                              Where did VLANs come from ?
                              So you do have a 192.168.200.1/24 interface ? (LAN, or VLAN doesn't matter, as long as it is set up correctly).

                              VLAN need a setup on the pfSense side, and on the smart 'VLAN capable side' switch side.

                              No "help me" PM's please. Use the forum, the community will thank you.
                              Edit : and where are the logs ??

                              A 1 Reply Last reply Reply Quote 0
                              • A Offline
                                azdeltawye @Gertjan
                                last edited by

                                @Gertjan said in Having trouble accessing NAS through VPN server:

                                Where did VLANs come from ?

                                huh??
                                I configured them when I designed the network years ago... You can see the different interfaces of my network from the screenshot on post #16. Here is a summary of how the network segments are defined:

                                8e26d849-2d6d-405f-9e9b-a3257f1a5682-image.png

                                Yes, all the layer 2 switches and APs are capable of VLAN tagging...

                                So when I log into my VPN server with my iPhone from a remote location, I am able to ping random devices on every VLAN listed above in my network. However, I cannot ping the Synology NAS (192.168.200.4). But, I am able to ping my backup 'NAS' (192.168.200.5). My backup 'NAS' is just an old Asus RT-AC86 router with a Samba SSD plugged into the USB port. I cannot access either NAS from the File Explorer app on my iphone.

                                Now when I am at home and my iPhone is on the 200 VLAN network, I can ping and access both NAS devices with the File Explorer app.

                                GertjanG 1 Reply Last reply Reply Quote 0
                                • GertjanG Offline
                                  Gertjan @azdeltawye
                                  last edited by

                                  @azdeltawye said in Having trouble accessing NAS through VPN server:

                                  huh??

                                  Don't worry. I thought you had a single pfSense LAN, 192.168.125.0/24 and a NAS using 192.168.200.4 on that LAN.
                                  That will fail of course.
                                  But solved now : you have more then one LAN ^^ Your NAS lives on the LAN called 'HOME' :

                                  481daab1-1e43-419d-9e7e-99026aea453d-image.png

                                  Check that :

                                  99b220ee-00af-42ab-b2bb-7db05055f0e4-image.png

                                  has been set to /24.

                                  Check that your OpenVPN interface firewall says :

                                  9752f332-864b-4fe2-978d-4be4171e900b-image.png

                                  Btw : You've two of them : 10.0.20.0/24 and 10.0.10.0/24.

                                  About :

                                  1aacbf53-f23b-47aa-829b-1c6cbb5d62f6-image.png

                                  I would presume that your iPad would have a 10.0.10.0/24 or 10.0.20.0/24 IP when connected to the VPN, not this 10.208.190.248 IP (where did that came from ?)

                                  No "help me" PM's please. Use the forum, the community will thank you.
                                  Edit : and where are the logs ??

                                  A 1 Reply Last reply Reply Quote 0
                                  • A Offline
                                    azdeltawye @Gertjan
                                    last edited by

                                    @Gertjan
                                    Actually, the NAS's live on the USER .200 network.
                                    7a8e6a4a-bd88-4746-b972-590669a71219-image.png
                                    Yes, it is a /24.

                                    dc59d4ee-7b17-45d3-adad-6b33724c9f4d-image.png
                                    4f971d77-9f42-4fa1-8a2d-ad35737c6473-image.png
                                    Yeah, I have the OpenVPN server subnets rule to allow all traffic.

                                    What advanced settings do you have in your VPN interface rule? I see a gear symbol next to the pass check mark. Is that something that may help?

                                    That private address assigned to my iPhone (10.208.190.248) is puzzling. It appears to be a Verizon thing. If I go to Starbucks and jump on their WiFi, or work, it shows the same address.. Just for kicks, I put that IP in the VPN interface rule shown above but that had no effect. My iPad does not have any of that since it has no SIM card.

                                    GertjanG 1 Reply Last reply Reply Quote 0
                                    • GertjanG Offline
                                      Gertjan @azdeltawye
                                      last edited by

                                      @azdeltawye said in Having trouble accessing NAS through VPN server:

                                      What advanced settings do you have in your VPN interface rule?

                                      Just the "Allow IP options" set :

                                      725c4fc0-313e-450b-86c5-e3df884e2000-image.png

                                      Probably not needed.

                                      Btw : my OpenVPN interface firewall rule set is empty :

                                      8104d901-73f3-4a8c-98d8-9e18c0621c08-image.png

                                      as I've created an "VPNS" for my OpenVPN server :

                                      c402e9c4-c11c-4bac-9f85-c0a7070d4b20-image.png

                                      so it's has it's own dedicated interface with rule set :

                                      9ba3fc32-ded8-4746-82c6-e93e22a2ef8c-image.png

                                      This is also most probably a way of doing things, and not important.

                                      No "help me" PM's please. Use the forum, the community will thank you.
                                      Edit : and where are the logs ??

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.