Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Nat on Tun?

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 3 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      ddvzlnz
      last edited by

      I have a wrap, the wan is the wireless card and it is a wireless client to an access poing.  If I plug in my laptop to the lan port I get dhcp, an ip address and I can surf.  Now the wrap is also an openvpn client to a openvpn server that hands out a default route so all traffic can go through it.  When I start the openvpn client it connects.  If I ssh into the wrap and go to shell I can ping and traceroute the outside world (from the wrap) and it goes throught the vpn as it should.  My laptop however attached to lan 1 can not get to the outside world.  I expected that the routing tables would handle it automaticly.

      Maybe it is late but I'm stuck.  Any ideas what I should try next?

      GT

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        Sounds like a routing problem or maybe the system facing the real WAN does not do nat for the remote subnet that your client is in. Can you show us a traceroute from the client to a public IP and show us a networkdiagram with IPs of the networks and devices? That would be helpful.

        1 Reply Last reply Reply Quote 0
        • GruensFroeschliG
          GruensFroeschli
          last edited by

          I'm not sure if this helps you but it might be worth reading:

          site-to-site
          http://forum.pfsense.org/index.php/topic,6056.0.html

          nat
          http://forum.pfsense.org/index.php/topic,6341.0.html

          We do what we must, because we can.

          Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

          1 Reply Last reply Reply Quote 0
          • D
            ddvzlnz
            last edited by

            Ok, I have more info.  It is still not working. First I'll start with the big picture, literally:

            BigPicture.png
            BigPicture.png_thumb

            1 Reply Last reply Reply Quote 0
            • D
              ddvzlnz
              last edited by

              Ok, I got it to work but not in a way that is useful outside of the lab.  Here are the remaining hurdles:

              I need to use tls auth and there is no way I can see yet to make the upload of the ta.key survive a reboot.  Maybe a full install on a microdrive…

              When I added the line to nat on the tun0 device to the lan subnet it worked, packets were passed from the lan to the tunnel but I don't know how to add the line into the pf.conf file permanently.  It seems to go away when the tunnel goes down and comes back up too and it of course goes away on reboot.

              Thank you for your assistance.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.