• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Yes, another "Can't ping the network behind the firewall" question.

Scheduled Pinned Locked Moved OpenVPN
7 Posts 2 Posters 2.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    benutne
    last edited by Aug 9, 2008, 12:26 AM

    What do I need to post for help and what should I take out for security reasons?  I suspect everyone wants the config file on the server and client, along with the log file for the client.  All those I can get.  My other concern is cleaning the logs/configs of sensitive data, which being new to OpenVPN, I have no idea what is and what isn't sensitive.

    1 Reply Last reply Reply Quote 0
    • B
      benutne
      last edited by Aug 9, 2008, 12:32 AM

      Sorry, I ought to clarify.  I've already got a site to site VPN working, and now I'm trying to get roadwarriors up.  The log shows no errors whatsoever and it appears to connect fine, but I get no access to things behind my firewall.  And I've followed this forum post to the letter.

      Thanks.

      1 Reply Last reply Reply Quote 0
      • G
        GruensFroeschli
        last edited by Aug 9, 2008, 1:16 AM

        Maybe you should start with a diagram and an accurate description what you're trying to achieve.

        Then what you already tried and how the result differs from what you want.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • B
          benutne
          last edited by Aug 9, 2008, 1:20 AM

          @GruensFroeschli:

          Maybe you should start with a diagram and an accurate description what you're trying to achieve.

          Then what you already tried and how the result differs from what you want.

          For my own sake or to help describe to problem to the forum?  I have a strong feeling its a NAT/firewall rule issue.  I'm not used to explicitly defining my firewall rules.  What about my question as to what is safe to post for config files/logs?

          1 Reply Last reply Reply Quote 0
          • G
            GruensFroeschli
            last edited by Aug 9, 2008, 6:58 AM Aug 9, 2008, 6:56 AM

            For the sake of me understanding your setup and finding out whats wrong.

            There is no firewall/NAT for OpenVPN per default.
            You have to enable manually Advanced outbound NAT to get NAT functionality.
            It's not possible to firewall the OpenVPN-interface at this time.
            So no this cannot be the problem ;)

            The configs/logs are safe to post. Just dont post the content of the key-files.
            You might want to remove the remote public IP's.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • B
              benutne
              last edited by Aug 19, 2008, 1:59 AM

              I got it working.  The NAT was a non issue since I just allow all outgoing NAT at the moment.  What was important to set up was the firewall rules allowing my Road Warrior subnet access using the correct gateway and port.  Thanks for the help.

              1 Reply Last reply Reply Quote 0
              • G
                GruensFroeschli
                last edited by Aug 19, 2008, 8:57 AM

                Could you desribe this a bit more?
                Because as i wrote before: there is no firewall for OpenVPN.

                We do what we must, because we can.

                Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received