Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    No Traffic inbound

    Scheduled Pinned Locked Moved OpenVPN
    15 Posts 2 Posters 2.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      Deactivate both of those rules on IPVANISH and OpenVPN unless you are looking for connections INBOUND from IPVANISH.

      If you are looking for connections INBOUND then IPVANISH has to forward a port to you if you are getting an RFC1918 address from them.

      Need to see your rules on LAN. Those are the rules that actually steer your traffic out the VPN.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • J
        Jumbosausage
        last edited by

        It's currently disabled here as when I do enable it all traffic from my torrent client stops, I lose internet connectivity from the torrentserver etc.

        1.PNG
        1.PNG_thumb

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          How do you expect traffic to route with the rule disabled? And that rule is TCP-only are you sure that's what you want?

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • J
            Jumbosausage
            last edited by

            Also it's my understanding I'd need inbound also for the torrent tracker to see me? Would changing the port forward rule here from WAN to IPVanish be what you mean or is this something at their end?

            1.PNG
            1.PNG_thumb

            1 Reply Last reply Reply Quote 0
            • J
              Jumbosausage
              last edited by

              @Derelict:

              How do you expect traffic to route with the rule disabled? And that rule is TCP-only are you sure that's what you want?

              I only disabled it to get it working for the time being on my WAN until I can figure this out.

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                To accept INBOUND connections IPVANISH needs to forward a port to you and you need to forward that port on the IPVANISH interface to your torrent node.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • J
                  Jumbosausage
                  last edited by

                  @Derelict:

                  To accept INBOUND connections IPVANISH needs to forward a port to you and you need to forward that port on the IPVANISH interface to your torrent node.

                  OK thanks. I've also tried disabling those IPVanish/OpenVPN rules and also changed the protocal to TCP/UDP but still no joy with outbound.

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    What do you mean by "no joy". What isn't working? Can you not ping? Not resolve names? what? It could be 1000 different things. "no joy" tells us nothing.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • J
                      Jumbosausage
                      last edited by

                      @Derelict:

                      What do you mean by "no joy". What isn't working? Can you not ping? Not resolve names? what? It could be 1000 different things. "no joy" tells us nothing.

                      I can ping the virtual IP address provided by IPVanish and I can resolve names, I just can't route any traffic through the tunnel. As soon as I switch the Gateway from my WAN connection I lose internet connectivity.

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        WHAT DO YOU MEAN "LOSE INTERNET CONNECTIVITY" ?

                        What stops working when you switch the gateway?

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • J
                          Jumbosausage
                          last edited by

                          @Derelict:

                          WHAT DO YOU MEAN "LOSE INTERNET CONNECTIVITY" ?

                          What stops working when you switch the gateway?

                          I can't access any web pages, I get the "This webpage is not available" message and  my torrent client stops seeding/downloading. I can however ping addresses such as Google.com for example. It just seems I have outbound communication but nothing inbound is working.

                          1 Reply Last reply Reply Quote 0
                          • DerelictD
                            Derelict LAYER 8 Netgate
                            last edited by

                            Does traceroute -n 8.8.8.8 go out the VPN or the WAN?

                            What does dig @8.8.8.8 www.google.com do?

                            If you are stuck in a Windows world and don't have reasonable troubleshooting tools, sorry.

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            1 Reply Last reply Reply Quote 0
                            • J
                              Jumbosausage
                              last edited by

                              Finally got this working, I've attached the config that is working but it seems my main issue was the advanced config in the client section. One thing that isn't working though is the port forwarding on the IPVanish interface but I know this is because they don't support it so I'll likely be changing to AirVPN shortly.

                              One other thing I didn't expect to see was the WAN traffic graph mirroring the IPVanish one. I know for sure that the traffic is leaving the correct interface and just presume this is normal?

                              Capture1.PNG
                              Capture1.PNG_thumb
                              Capture2.PNG
                              Capture2.PNG_thumb
                              Capture3.PNG
                              Capture3.PNG_thumb
                              Capture4.PNG
                              Capture4.PNG_thumb
                              Capture5.PNG
                              Capture5.PNG_thumb
                              Capture7.PNG
                              Capture7.PNG_thumb

                              1 Reply Last reply Reply Quote 0
                              • DerelictD
                                Derelict LAYER 8 Netgate
                                last edited by

                                OpenVPN traffic is going out WAN, comrade.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.