• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

LAN to LAN - Problems ;)

Scheduled Pinned Locked Moved OpenVPN
17 Posts 6 Posters 5.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M Offline
    marvosa
    last edited by Aug 26, 2013, 3:15 PM

    On the server-side (DD-WRT), it looks like you forgot to enter the remote network.  You need to add the following to your server-side config:

    route 192.168.2.0 255.255.255.0

    1 Reply Last reply Reply Quote 0
    • D Offline
      da_blubb
      last edited by Aug 26, 2013, 8:21 PM Aug 26, 2013, 8:06 PM

      First of all, thanks for your help and the patience to unterstand my "english" :)

      I updated the network-diagram, because i may not clearly pointed out was my goal is.

      I added the route to the server, but it still drops the packages… Same message.

      UPDATE:
      I tried to ping my ubuntu-server from my pfsense-box and this worked.
      Seems i only have to make the 192.168.1.0/24-Network available for the other clients in the 192.168.2.0/24-Network.
      But i really dont know how...

      1 Reply Last reply Reply Quote 0
      • P Offline
        phil.davis
        last edited by Aug 31, 2013, 2:36 PM

        Now I see the OpenVPN server is behind the DD-WRT. I guess DD-WRT must be port-forwarding 1194 through to the OpenVPN server.
        You are going to have some issues with your clients at the DD-WRT end when they try to reply - they will have DD-WRT as their ordinary gateway. DD-WRT will need to route back to the OpenVPN server for traffic to 192.168.2.0/24…

        But for now, what is the OpenVPN server running on?
        I guess your original error messages mean that it is rejecting the packets coming in across the OpenVPN link from 192.168.2.188. That needs to be fixed somehow.

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • D Offline
          da_blubb
          last edited by Sep 15, 2013, 9:16 AM

          The Port-Forwarding is already done.

          The OpenVPN-Serve is running on a Ubuntu-Server 12.04.

          Any ideas how to set up a specific gateway for the 192.168.0.2/24-Net?

          1 Reply Last reply Reply Quote 0
          • J Offline
            johnpoz LAYER 8 Global Moderator
            last edited by Sep 15, 2013, 1:32 PM

            Why don't you just move the openvpn connection to dd-wrt or put pfsense where dd-wrt is?

            Your over complicating the setup, putting your vpn endpoint behind a nat and not as the default gateway for the network your tying to access is not an ideal way to go about it.

            Why are trying to use pfsense behind dd-wrt?  I personally would just use pfsense and remove dd-wrt completely.. But if you want to use it - its supports openvpn as well.  http://www.dd-wrt.com/wiki/index.php/OpenVPN

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07 | Lab VMs 2.8, 25.07

            1 Reply Last reply Reply Quote 0
            • D Offline
              da_blubb
              last edited by Sep 15, 2013, 5:08 PM Sep 15, 2013, 2:21 PM

              Well the DD-WRT router is just a consumer-router with horrible throughput(600-800kb/s openvpn-performance) and i need at least 2mb/s.
              I currently dont got the hardware to build a new pfsense-box.

              UPDATE:
              The speed was when using openvpn on the dd-wrt-router

              1 Reply Last reply Reply Quote 0
              • J Offline
                johnpoz LAYER 8 Global Moderator
                last edited by Sep 15, 2013, 3:17 PM

                So you need 2mbps, and dd-wrt does 800kbps – how is putting openvpn on a box behind dd-wrt going to fix that?

                So replace the hardware running dd-wrt on now that something can handle the bandwidth you need and then run openvpn on that.  Depending on the hardware - just run pfsense vs dd-wrt.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07 | Lab VMs 2.8, 25.07

                1 Reply Last reply Reply Quote 0
                • D Offline
                  da_blubb
                  last edited by Sep 15, 2013, 3:49 PM

                  The box behind the DD-WRT router is a ubuntu-server.
                  The ubuntu-server got a 4-core-xeon cpu. I think this should handle the 2 mb/s

                  1 Reply Last reply Reply Quote 0
                  • D Offline
                    doktornotor Banned
                    last edited by Sep 15, 2013, 3:54 PM

                    Does not exactly matter what's behind the bottleneck. :D

                    1 Reply Last reply Reply Quote 0
                    • D Offline
                      da_blubb
                      last edited by Sep 15, 2013, 4:25 PM Sep 15, 2013, 4:04 PM

                      The dd-wrt-router is only the bottleneck when im running the openvpn-service on it.
                      So whats your point? Or am i missing something?

                      I dont want to replace the router, because i dont got the hardware
                      and i dont want to spend the money just for running openvpn on it.

                      1 Reply Last reply Reply Quote 0
                      • D Offline
                        doktornotor Banned
                        last edited by Sep 15, 2013, 4:25 PM

                        I still do not get why are you running OpenVPN thru an obvious bottleneck. Make an AP from it on your LAN, stop using it as router.

                        1 Reply Last reply Reply Quote 0
                        • D Offline
                          da_blubb
                          last edited by Sep 15, 2013, 4:26 PM

                          I dont get why the dd-wrt router is the bottleneck?

                          1 Reply Last reply Reply Quote 0
                          • D Offline
                            doktornotor Banned
                            last edited by Sep 15, 2013, 4:28 PM

                            Sigh… because you said it yourself?  As suggested by myself and other people above, move pfS where the DD-WRT is right now and use the DD-WRT router as an AP. Otherwise, since this obviously does not go anywhere - have a nice day.

                            1 Reply Last reply Reply Quote 0
                            • K Offline
                              kejianshi
                              last edited by Sep 15, 2013, 4:32 PM

                              CaptainWTF could walk him through this…  He figured this out and its fresh in his mind (-:

                              1 Reply Last reply Reply Quote 0
                              • D Offline
                                da_blubb
                                last edited by Sep 15, 2013, 5:06 PM

                                Ok my fault. I was talking about 800kb/s throughput when running openvpn on the dd-wrt router.
                                I tought this was clear due to the advice in the previous post.
                                Thats why i want to use the ubuntu-server.

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                  [[user:consent.lead]]
                                  [[user:consent.not_received]]