Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN on dual WAN - cannot reach clients

    Scheduled Pinned Locked Moved OpenVPN
    15 Posts 2 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E Offline
      eddi1984
      last edited by

      Hi folks,

      got a problem with OpenVPN. Hope somebody can point me into the right direction.

      I have pfsense 2.2.4 setup with Dual WAN (2 seperate providers) for failover and loadbalance. That is working great.

      I also have setup OpenVPN, and I can connect and establish a connection on both WAN connections.
      OpenVPN setup for "Interface" is "localhost".
      Than I forward the UDP connection on each WAN to "localhost or 127.0.0.1".
      This was the only way I could get OpenVPN setup to work on both WAN interfaces and this is the recommended setup here on the forum.

      Now, I can ping the pfsense box (172.24.0.1) no problem, but, I cannot ping any other clients. I am trying to get RDP working, but a simple ping does also not work.

      What am I missing?

      Thanks.

      1 Reply Last reply Reply Quote 0
      • H Offline
        heper
        last edited by

        probably firewall rules or routes or both.

        1 Reply Last reply Reply Quote 0
        • E Offline
          eddi1984
          last edited by

          Hope the attached pictures help.

          Gateway.PNG
          Gateway.PNG_thumb
          NAT.PNG
          NAT.PNG_thumb
          OpenVPN.PNG
          OpenVPN.PNG_thumb
          PortForward.PNG
          PortForward.PNG_thumb
          StaticRoute.PNG
          StaticRoute.PNG_thumb
          ![VPN Interface.PNG](/public/imported_attachments/1/VPN Interface.PNG)
          ![VPN Interface.PNG_thumb](/public/imported_attachments/1/VPN Interface.PNG_thumb)
          WAN_S.PNG
          WAN_S.PNG_thumb
          WAN_T.PNG
          WAN_T.PNG_thumb

          1 Reply Last reply Reply Quote 0
          • E Offline
            eddi1984
            last edited by

            Anybody?

            1 Reply Last reply Reply Quote 0
            • H Offline
              heper
              last edited by

              rules seem ok

              must be routes then … show pics of the vpn config for more insight pls

              1 Reply Last reply Reply Quote 0
              • E Offline
                eddi1984
                last edited by

                I hope the pictures help. I dont know howto get the text version of the OpenVPN Server config.

                If you can tell me where to find it, I can upload that as well.

                VPNConfig_1.PNG
                VPNConfig_1.PNG_thumb
                VPNConfig_2.PNG
                VPNConfig_2.PNG_thumb
                VPNConfig_3.PNG
                VPNConfig_3.PNG_thumb

                1 Reply Last reply Reply Quote 0
                • H Offline
                  heper
                  last edited by

                  you don't need to push your tunnel network, you need to push you lan network

                  1 Reply Last reply Reply Quote 0
                  • E Offline
                    eddi1984
                    last edited by

                    I removed the push to Tunnel network and added:

                    push "route 172.24.0.0 255.255.0.0";

                    But it did not solve my problem.

                    It seems to me, that the Tunnel is going to localhost, but is stuck there and cannot reach the LAN. I can connect via VPN on both WAN interfaces and access the pfsense box web interface and access the internet, but not the LAN.

                    1 Reply Last reply Reply Quote 0
                    • H Offline
                      heper
                      last edited by

                      do the routes show up in the routing tables on the clients ?

                      1 Reply Last reply Reply Quote 0
                      • E Offline
                        eddi1984
                        last edited by

                        How can I check that?

                        1 Reply Last reply Reply Quote 0
                        • H Offline
                          heper
                          last edited by

                          http://www.howtogeek.com/howto/ubuntu/display-the-routing-table-in-either-windows-or-ubuntu/

                          1 Reply Last reply Reply Quote 0
                          • E Offline
                            eddi1984
                            last edited by

                            see picture of routing table.

                            As far as I can tell, the route does show up properly.

                            ![Routing Table.PNG](/public/imported_attachments/1/Routing Table.PNG)
                            ![Routing Table.PNG_thumb](/public/imported_attachments/1/Routing Table.PNG_thumb)

                            1 Reply Last reply Reply Quote 0
                            • H Offline
                              heper
                              last edited by

                              yes but you are having a route for 2 subnets ??

                              a /16 one and a /24 both pointing towards 172.24.0.0 …. why is that ?

                              1 Reply Last reply Reply Quote 0
                              • E Offline
                                eddi1984
                                last edited by

                                Hi,

                                I noticed that as well and removed it already. It was, because of the push entry that was pointing to /16. i changed it to /24. Now it only shows one route to 172.24.0.0 /24.

                                1 Reply Last reply Reply Quote 0
                                • E Offline
                                  eddi1984
                                  last edited by

                                  Hi,

                                  anybody have any further ideas? This is still not working, but I cannot find the issue. All settings look fine.

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.