Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    HOWTO Road Warrior to remote Subnet on LAN

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 4 Posters 4.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      Guest
      last edited by

      The LAN user default gateway is the Corporate FW 172.27.110.1, and can't change it. I've already working a IPCOP+OpenVPN doing this, without any problem, the configuration was made about two years ago, but  I don't have all the details on how it was done.

      1 Reply Last reply Reply Quote 0
      • Cry HavokC
        Cry Havok
        last edited by

        If it works with IPCop then it suggests you haven't fully copied the configuration. You need to compare the client and server configurations, and the routes for the VPN servers, and see what is different.

        1 Reply Last reply Reply Quote 0
        • ?
          Guest
          last edited by

          I'm sure I didn't copy everything, but don't now what's missing, my knowledge of linux or FreeBSD is very limited.

          I guess I've to do some kind of NAT or bridging from openvpn clients sunet (10.0.8.x) to lan (172.27.110.x), so they look like local users for the corp network firewall, but  I'm not sure how to do this.

          So if somebody has a suggestion, I'll appreciate it very much.

          1 Reply Last reply Reply Quote 0
          • Cry HavokC
            Cry Havok
            last edited by

            With 2.0 (still in pre-release form) that happens automatically ISTR. With 1.2.3 you have to manually configure the NAT - a search of the forum should provide details.

            1 Reply Last reply Reply Quote 0
            • ?
              Guest
              last edited by

              Thanks for your comments, I'm working with the latest 2.0 RC1, so NAT is automatic? or I've to set something?

              Remote servers at corporate network, see what IP? the PFsense LAN IP?

              regards
              Alfredo

              1 Reply Last reply Reply Quote 0
              • Cry HavokC
                Cry Havok
                last edited by

                You probably want to search the forum ;)

                I've not used OpenVPN with pfSense 2.0 so I can only go by what others have posted.

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  The kind of NAT you need is not automatic. You need to be on manual outbound NAT and have an outbound NAT rule on LAN that matches traffic from the OpenVPN client subnet, to the "corporate" subnet(s), that gets NAT applied in some way. You can simply NAT to the Interface address if you want, then it would appear to come from the firewall's IP on that segment, or you could add a proxy ARP or CARP VIP and use that.

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • ?
                    Guest
                    last edited by

                    Thanks JIMP, I've looked everywhere in the forum, and I didn´t find anything useful. So I'm trying to follow your instructions, and did the follwing:

                    1.- Create a virtual IP (172.27.1100.156)
                    2.- Asign outbout NAT to network 10.0.8.0/24 to LAN IP 172.27.110.156

                    So I guess users on VPN subnet 10.0.8.x will show 172.27.110.156 to LAN or corporate devices, or I'm wrong?

                    Config as show in next pictures, please tell me if I'm ok or what's wrong.

                    VPN_Subnet.png
                    VPN_Subnet.png_thumb
                    VPN_LAN_IP_NAT.png
                    VPN_LAN_IP_NAT.png_thumb
                    OutBound_NAT_VPN_to_LANIP.png
                    OutBound_NAT_VPN_to_LANIP.png_thumb

                    1 Reply Last reply Reply Quote 0
                    • jimpJ
                      jimp Rebel Alliance Developer Netgate
                      last edited by

                      Yes, OpenVPN client traffic leaving LAN will appear to come from 172.27.110.156 to things on (or beyond) LAN.

                      You may not want that for traffic to LAN IPs, so you may want to adjust that so the nat doesn't get applied when going to the LAN subnet, only to other subnets.

                      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      1 Reply Last reply Reply Quote 0
                      • ?
                        Guest
                        last edited by

                        I've just tested using a 3G modem and works perfectly, I can reach any service available to LAN users form OpenVPN Users.

                        Thanks for your help

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.