Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can ping server but not rest of network.

    Scheduled Pinned Locked Moved OpenVPN
    30 Posts 5 Posters 15.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      andrew502
      last edited by

      Is it other VPN clients you are unable to ping?  IF so there is an option "Client-to-client VPN" that you need to tick in the Open VPN  configuration on the PFsense firewall to allow this.  If you're referring to devices behind the firewall then check if your firewall rule allow any to any for the Open VPN port, otherwise it might cause this issue.

      Do you receive the route for the network in your routing table?  Type "route print" from a command prompt to check.  IF the IP address range of your network is the same as the one behind your firewall this could cause a problem.

      Hope that helps.

      1 Reply Last reply Reply Quote 0
      • T
        Thibaut
        last edited by

        Hello (and sorry for my bad english, im french…)

        I have the same problem ... See my OpenVPN server configuration :

        I'm on local network 10.187.91.0/22 and i create this VPN on this network. I have a local network 192.168.1.0/24, and I want to access to it with a VPN.

        With this configuration, I can ping my VPN Server with the address 192.168.1.254, but not the rest of this local network (192.168.1.245 for exemple…)

        This is my rules of my firewall :

        WAN : UDP  *          *  *  1194 (OpenVPN)  *
        LAN  : *          LAN net  *  *  *                          *

        So, it's a problem ...

        1 Reply Last reply Reply Quote 0
        • Cry HavokC
          Cry Havok
          last edited by

          Is the OpenVPN server the default gateway for the network behind it?

          1 Reply Last reply Reply Quote 0
          • T
            Thibaut
            last edited by

            Heum… Yes, pfSense is the default gateway on 192.168.1.0/24 sub-network !

            1 Reply Last reply Reply Quote 0
            • Cry HavokC
              Cry Havok
              last edited by

              And on the remote client, when the link is up, what does "netstat -rn" show?

              1 Reply Last reply Reply Quote 0
              • T
                Thibaut
                last edited by

                That …

                thibaut@PC-de-Thibaut:~$ netstat -rn
                Table de routage IP du noyau
                Destination     Passerelle      Genmask         Indic   MSS Fenêtre irtt Iface
                192.168.2.1     192.168.2.5     255.255.255.255 UGH       0 0          0 tun0
                192.168.2.5     0.0.0.0         255.255.255.255 UH        0 0          0 tun0
                172.16.119.0    0.0.0.0         255.255.255.0   U         0 0          0 vmnet1
                192.168.1.0     192.168.2.5     255.255.255.0   UG        0 0          0 tun0
                172.16.74.0     0.0.0.0         255.255.255.0   U         0 0          0 vmnet8
                10.187.88.0     0.0.0.0         255.255.252.0   U         0 0          0 eth0
                169.254.0.0     0.0.0.0         255.255.0.0     U         0 0          0 eth0
                0.0.0.0         10.187.88.245   0.0.0.0         UG        0 0          0 eth0
                
                
                1 Reply Last reply Reply Quote 0
                • Cry HavokC
                  Cry Havok
                  last edited by

                  Routing looks good.  Does the OpenVPN server end have another network that's 192.168.1.x/24?

                  1 Reply Last reply Reply Quote 0
                  • T
                    Thibaut
                    last edited by

                    My pfSenseBox is in two network :
                    WAN : 10.187.88.0/22 (address 10.187.88.9)
                    LAN : 192.168.1.0/24 (address 10.187.88.254, it's the gateway of the 192.168.1.0/24 subnet)

                    So i think that the OpenVPN server is on the 192.168.1.0/24 network …

                    1 Reply Last reply Reply Quote 0
                    • Cry HavokC
                      Cry Havok
                      last edited by

                      I can't see an obvious problem.  I'd check things like firewall settings (on both ends), drop a packet sniffer in to see if the packets are making it through pfSense (ISTR that tcpdump is installed by default on pfSense) and check to see if you can ping from the 192.168.1.0/24 network to the 192.168.2.0/24 network.

                      1 Reply Last reply Reply Quote 0
                      • T
                        Thibaut
                        last edited by

                        Arf ….

                        Ok thanks for your help ! A return to work on Monday, so see you soon !

                        1 Reply Last reply Reply Quote 0
                        • T
                          Thibaut
                          last edited by

                          Hello !

                          So, i can ping 192.168.2.0/24 address from 192.168.1.0/24 subnet. But from 10.187.88.0/22, i ping 192.168.1.254 but not the rest of the 192.168.1.0/24 subnet :(

                          1 Reply Last reply Reply Quote 0
                          • Cry HavokC
                            Cry Havok
                            last edited by

                            I think a diagram is required to make that last post make sense.  You're implying that you're trying to ping from outside the pfSense host, on the WAN, to the LAN.

                            1 Reply Last reply Reply Quote 0
                            • T
                              Thibaut
                              last edited by

                              PC1 192.168.2.6 (tun0) –-------------- 10.187.88.8 (WAN) pfSense 192.168.1.254 (LAN) ------------------ 192.168.1.245 (LAN) PC2

                              pfSense have also 192.168.2.5 for the VPN Server.

                              ping from PC2 to PC1 work !
                              ping from PC1 to PC2 doesn't work !

                              and i want to access to LAN since WAN with VPN server

                              1 Reply Last reply Reply Quote 0
                              • Cry HavokC
                                Cry Havok
                                last edited by

                                Right, then look at the firewall settings on PC2.  You may find that it's blocking ping requests.

                                1 Reply Last reply Reply Quote 0
                                • T
                                  Thibaut
                                  last edited by

                                  thanks for your help

                                  But my firewall on PC2 is disable …

                                  I can see the request from 192.168.2.6 to 192.168.1.245 with tcpdump of pfSense, but not the reply.

                                  1 Reply Last reply Reply Quote 0
                                  • Cry HavokC
                                    Cry Havok
                                    last edited by

                                    Then your problem is with the host 192.168.1.245.  Check that it's default gateway is correct, check to see that it's receiving the packets, do all the basic troubleshooting steps on that host.

                                    1 Reply Last reply Reply Quote 0
                                    • T
                                      Thibaut
                                      last edited by

                                      The problem doesn't become on that host because there is the same problem with an other PC with an other IP address…

                                      thx for your help ...

                                      1 Reply Last reply Reply Quote 0
                                      • Cry HavokC
                                        Cry Havok
                                        last edited by

                                        Well, start there.  If you're seeing packets enter the LAN but not return to pfSense then something you've posted here is obviously wrong.  The three possibilities are:

                                        1. The hosts don't use the pfSense host as their default gateway
                                        2. The static routes on the LAN clients are wrong
                                        3. They run firewalls

                                        Eliminate those one at a time, what's left is the only possibility.

                                        1 Reply Last reply Reply Quote 0
                                        • T
                                          Thibaut
                                          last edited by

                                          1. The static routes on the LAN clients

                                          What's that ?  ???

                                          1 Reply Last reply Reply Quote 0
                                          • Cry HavokC
                                            Cry Havok
                                            last edited by

                                            Static routes tell clients how to reach networks that are attached to something other than your default gateway.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.