Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Open VPN Site-to-Site not routing from Clients

    Scheduled Pinned Locked Moved OpenVPN
    11 Posts 5 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      heper
      last edited by

      try filling in the tunnel network

      1 Reply Last reply Reply Quote 0
      • lawrencesystemsL
        lawrencesystems
        last edited by

        I have tried it the the tunnel filled in, I have tried it with adding the routes for the other network.  Either way I can only ping the clients at the main site via the pfSense box and not from the clients at the remote site.

        1 Reply Last reply Reply Quote 0
        • D
          divsys
          last edited by

          Is this a Shared key or SSL/TLS setup?

          -jfp

          1 Reply Last reply Reply Quote 0
          • lawrencesystemsL
            lawrencesystems
            last edited by

            Shared key.  Here is the log from the remote / client side when connecting.  I can ssh into the remote box and once OpenVPN connects I can ping clients from both sides of the network, I just can not get the clients on the remote site to see the clients at at the main office.

            1 Reply Last reply Reply Quote 0
            • H
              heper
              last edited by

              @lawrencesystems:

              I just can not get the clients on the remote site to see the clients at at the main office.

              what do you mean? if you can ping from both sides, then there shouldn't be any issue's (unless you allow icmp, but block everything else).

              if this is about "windows neighborhood network' : it doesn't route, it only broadcasts.
              setup proper dns.

              if you want to send broadcasts over your vpn you need a different type of setup: https://community.openvpn.net/openvpn/wiki/BridgingAndRouting
              ^^^^
              don't do it, broadcasts waste too much precious bandwidth

              1 Reply Last reply Reply Quote 0
              • lawrencesystemsL
                lawrencesystems
                last edited by

                I can ping / access the main sites lan devices from the remote pfSense box.  But NONE of the clients on the remote site can reach clients on the main site.

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  @lawrencesystems:

                  I can ping / access the main sites lan devices from the remote pfSense box.  But NONE of the clients on the remote site can reach clients on the main site.

                  What do you mean by "reach"?  What are you trying to do?

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • D
                    doktornotor Banned
                    last edited by

                    @Derelict:

                    What do you mean by "reach"?

                    Most likely "I'm pinging and the Windows firewall is silently blocking that…"

                    1 Reply Last reply Reply Quote 0
                    • lawrencesystemsL
                      lawrencesystems
                      last edited by

                      The clients that I am reaching are linux boxes and I can ping them fine from the remote pfSense box once the VPN connects.  The clients at the remote site that are behind the connected pfSense box can not ping / reach clients on the other side at the main site.

                      1 Reply Last reply Reply Quote 0
                      • H
                        heper
                        last edited by

                        check fw rules on their respective LAN-tabs

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.