Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    HOWTO Road Warrior to remote Subnet on LAN

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 4 Posters 4.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rwebb616
      last edited by

      What is the lan user's default gateway set to and how do they access the corporate network?  Do they have static routes?

      -Rich

      1 Reply Last reply Reply Quote 0
      • ?
        Guest
        last edited by

        The LAN user default gateway is the Corporate FW 172.27.110.1, and can't change it. I've already working a IPCOP+OpenVPN doing this, without any problem, the configuration was made about two years ago, but  I don't have all the details on how it was done.

        1 Reply Last reply Reply Quote 0
        • Cry HavokC
          Cry Havok
          last edited by

          If it works with IPCop then it suggests you haven't fully copied the configuration. You need to compare the client and server configurations, and the routes for the VPN servers, and see what is different.

          1 Reply Last reply Reply Quote 0
          • ?
            Guest
            last edited by

            I'm sure I didn't copy everything, but don't now what's missing, my knowledge of linux or FreeBSD is very limited.

            I guess I've to do some kind of NAT or bridging from openvpn clients sunet (10.0.8.x) to lan (172.27.110.x), so they look like local users for the corp network firewall, but  I'm not sure how to do this.

            So if somebody has a suggestion, I'll appreciate it very much.

            1 Reply Last reply Reply Quote 0
            • Cry HavokC
              Cry Havok
              last edited by

              With 2.0 (still in pre-release form) that happens automatically ISTR. With 1.2.3 you have to manually configure the NAT - a search of the forum should provide details.

              1 Reply Last reply Reply Quote 0
              • ?
                Guest
                last edited by

                Thanks for your comments, I'm working with the latest 2.0 RC1, so NAT is automatic? or I've to set something?

                Remote servers at corporate network, see what IP? the PFsense LAN IP?

                regards
                Alfredo

                1 Reply Last reply Reply Quote 0
                • Cry HavokC
                  Cry Havok
                  last edited by

                  You probably want to search the forum ;)

                  I've not used OpenVPN with pfSense 2.0 so I can only go by what others have posted.

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    The kind of NAT you need is not automatic. You need to be on manual outbound NAT and have an outbound NAT rule on LAN that matches traffic from the OpenVPN client subnet, to the "corporate" subnet(s), that gets NAT applied in some way. You can simply NAT to the Interface address if you want, then it would appear to come from the firewall's IP on that segment, or you could add a proxy ARP or CARP VIP and use that.

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • ?
                      Guest
                      last edited by

                      Thanks JIMP, I've looked everywhere in the forum, and I didn´t find anything useful. So I'm trying to follow your instructions, and did the follwing:

                      1.- Create a virtual IP (172.27.1100.156)
                      2.- Asign outbout NAT to network 10.0.8.0/24 to LAN IP 172.27.110.156

                      So I guess users on VPN subnet 10.0.8.x will show 172.27.110.156 to LAN or corporate devices, or I'm wrong?

                      Config as show in next pictures, please tell me if I'm ok or what's wrong.

                      VPN_Subnet.png
                      VPN_Subnet.png_thumb
                      VPN_LAN_IP_NAT.png
                      VPN_LAN_IP_NAT.png_thumb
                      OutBound_NAT_VPN_to_LANIP.png
                      OutBound_NAT_VPN_to_LANIP.png_thumb

                      1 Reply Last reply Reply Quote 0
                      • jimpJ
                        jimp Rebel Alliance Developer Netgate
                        last edited by

                        Yes, OpenVPN client traffic leaving LAN will appear to come from 172.27.110.156 to things on (or beyond) LAN.

                        You may not want that for traffic to LAN IPs, so you may want to adjust that so the nat doesn't get applied when going to the LAN subnet, only to other subnets.

                        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        1 Reply Last reply Reply Quote 0
                        • ?
                          Guest
                          last edited by

                          I've just tested using a 3G modem and works perfectly, I can reach any service available to LAN users form OpenVPN Users.

                          Thanks for your help

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.