Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to Correctly Modify Routes for OpenVPN Clients?

    Scheduled Pinned Locked Moved OpenVPN
    13 Posts 3 Posters 6.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      strick1226
      last edited by

      OK, another update.

      My current custom line in pfSense is:

      push "redirect-gateway"
      

      In Windows, when I do an ipconfig /all it shows my default gateway and dns for the opvn adapter as 192.168.200.5.  Where is it getting that?!  My "address pool" is set to 192.168.200.0/24.

      My pfSense's LAN interface is 192.168.50.1.  I'm stumped.

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG Offline
        GruensFroeschli
        last edited by

        if you want to use the redirect option, try reading the official openVPN howto:
        http://openvpn.net/howto.html#redirect

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • S Offline
          strick1226
          last edited by

          Thanks for the link!  I read over the howto 500 times last night but missed this part.

          Hopefully you can set this so it's a partial redirect, only for certain networks/addresses?  Will try this tonight.

          Thanks again!

          1 Reply Last reply Reply Quote 0
          • S Offline
            strick1226
            last edited by

            OK, I tried putting this in my custom options line in the pfSense OpenVPN server settings:

            push "redirect-gateway def1"
            

            Still no go.  It looks like I have DNS, as a tracert shows name resolution is working, but it dies at the gateway address of the OpenVPN tunnel (in this case, my machine is at 192.168.51.6, the gateway is displayed as 192.168.51.5).

            Do I have to add extra rules somewhere to allow the traffic?  Looking through this m0n0wall guide it sounds like they have a very handy OpenVPN tab in the firewall rules:

            http://www.closeconsultants.com/~peter/m0n0-ovpn-wifi.html  (all the way at the bottom)

            I can't find anything that looks like a way to specify to allow OpenVPN traffic to utilize the pfSense gateway…

            1 Reply Last reply Reply Quote 0
            • S Offline
              strick1226
              last edited by

              OK, I think I finally have this figured out.

              Sorta.

              I misunderstood the correct address range assignments.

              My setup:

              LAN: 192.168.50.1

              Was trying to set OpenVPN machines to address pool of 192.168.200.0/24.  Not working…

              Just tried 192.168.50.0/25 for my address pool.  Holy crap it works!

              I thought that was going to overrun the original IP range...
              I should have read up more on TCPIP :)

              1 Reply Last reply Reply Quote 0
              • S Offline
                strick1226
                last edited by

                OK…

                So if I set my OpenVPN machines address pool to 192.168.50.0/25 then I can access all addresses through the VPN--EXCEPT my workstations from 192.168.50.60-65 .
                If I set my OpenVPN machines address pool to 192.168.51.0/25 then I can access my workstations from 192.168.50-65, but not a single other thing.

                Am I missing something really basic here?  Sorry if this is a stupid question...

                1 Reply Last reply Reply Quote 0
                • L Offline
                  luma
                  last edited by

                  I think you forgot to enable advanced outbound NAT for your ovpn client network (ex : 192.168.200.0/24).

                  So you will be allowed to go out throught your OVPN server!

                  1 Reply Last reply Reply Quote 0
                  • S Offline
                    strick1226
                    last edited by

                    luma,

                    Thanks for the reply.  Man, I hope this is it!  :)

                    Will try tonight and report back.

                    1 Reply Last reply Reply Quote 0
                    • L Offline
                      luma
                      last edited by

                      I hope too :)

                      1 Reply Last reply Reply Quote 0
                      • S Offline
                        strick1226
                        last edited by

                        luma,

                        That's EXACTLY what it was!!!!

                        I owe you a cold one!  Heck, make that 12.  :D

                        Thanks for your help!!!

                        1 Reply Last reply Reply Quote 0
                        • L Offline
                          luma
                          last edited by

                          Good news!

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.