Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Clients connected to VPN cannot access DMZ

    Firewalling
    2
    3
    2.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mbaechtold
      last edited by

      Hi there

      I have a simple WAN, LAN, DMZ setup up and running.
      In the DMZ, there is a VPN (L2TP) server up and running (no, I don't use the built-in VPN service from pfSense for various reasons).
      External clients are able to establish a VPN connection, this works fine. The VPN server assigns IPs from the LAN subnet.
      The problem is, the users cannot access a server in the DMZ, this is blocked by the default deny rule:

      | If | Source | Destination | Proto |
      | DMZ | 192.168.118.51:51183 | 17.149.36.174:5223 | TCP:S |

      I thought about various problems:

      • Assigning LAN IPs by the VPN server
      • Firewall rules of DMZ missing

      Does anybody have a hint?

      1 Reply Last reply Reply Quote 0
      • M
        mbaechtold
        last edited by

        Some other ideas

        • VPN server should assign IPs from a new subnet that does not exist yet (say 192.168.115.0), maybe I'll have to find out, what virtual IPs are on pfSense
        • Maybe outbound NAT will help?

        Any ideas?

        1 Reply Last reply Reply Quote 0
        • C
          CarWizard
          last edited by

          i am developing a customized application for filemaker and i have vpn client installed..i have to get content from linkedin and store them in a local storage…i need your guide

          Diesel Cologne
          Ralph Lauren Perfume

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.