• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

OpenVpn Nat problem

Scheduled Pinned Locked Moved OpenVPN
4 Posts 2 Posters 2.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Y
    yena
    last edited by Oct 22, 2008, 8:46 AM Oct 22, 2008, 8:44 AM

    Hi,
    I've been banging my head against the wall on this issue for a couple of days and need some help. I am running 1.2 STABLE
    and i have setup OpenVPN.
    I would like to connect from internet to the protected server in the LAN :

    INTERNET –---> (wan 83.103.59.189 ) Pfsense ( lan 192.168.1.1) -----> ( 192.168.1.2) Server web,ftp,telnet..

    I successfully Open and connect from a Windows Client to the Pfsense VPN server but i can't connect to the Server..
    it seem a Nat problem.
    When i open the VPN i use the VPN IP to connect to the server: telnet 192.168.3.1

    My OpenVPN Pfsense settings:
    Protocol: UDP
    Dynamic IP: Yes
    Local port: 1194
    Address pool: 192.168.3.0/24
    Use static IPs: No
    Local network:
    Remote network:
    Client-to-client VPN:
    Cryptography: BF-CBC (128-bit)
    Authentication method: PKI
    LZO compression: yes

    Nat settings:
    Automatic outbound NAT rule generation (IPsec passthrough)

    I attach the Firewall Rules and other settings

    lan-fw.gif
    lan-fw.gif_thumb
    OpenVPN.gif
    OpenVPN.gif_thumb
    outbond.gif
    outbond.gif_thumb
    port-forward.gif
    port-forward.gif_thumb
    wan-fw.gif
    wan-fw.gif_thumb
    win-vpn.gif
    win-vpn.gif_thumb

    1 Reply Last reply Reply Quote 0
    • K
      kpa
      last edited by Oct 22, 2008, 10:10 AM

      The address pool (192.168.3.0/24 in your case) is just for the point-to-point addresses of the tunnel interface, you can't reach anything on your LAN using those addresses, you have to use the LAN network addresses to connect to any host on your LAN.

      1 Reply Last reply Reply Quote 0
      • Y
        yena
        last edited by Oct 22, 2008, 10:45 AM

        THANKSSS !! Yes this is my error  :o

        1 Reply Last reply Reply Quote 0
        • Y
          yena
          last edited by Oct 22, 2008, 11:09 AM

          Can i do the same with PPTP ?
          Or PPTP enable connection only from the same natwork of WAN ?
          Because i try it and i can connect to 192.168.1.2 only from WAN class..

          Thanks !

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received