Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [SOLVED] Unable to reach pfsense or any computer on its subnet from VPN server

    Scheduled Pinned Locked Moved OpenVPN
    18 Posts 2 Posters 4.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      And where do they state that is supported??

      Your going to have to put a public IP on your instance that is running, not some port forward..

      What is it that you need btw??  Can I fire up a google compute instance for low cost or free for testing?

      I see they have a $300 60 day free trial, signing up..  So what is it exactly your wanting to accomplish?

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • F
        FuriousGeorge
        last edited by

        @johnpoz:

        And where do they state that is supported??

        Your going to have to put a public IP on your instance that is running, not some port forward..

        I don't want to assume it isn't.

        @johnpoz:

        What is it that you need btw??  Can I fire up a google compute instance for low cost or free for testing?

        No but I can make one for you.

        @johnpoz:

        I see they have a $300 60 day free trial, signing up..  So what is it exactly your wanting to accomplish?

        That's for support.  An instance might only cost you $5 per month if you get the teeny tiny one.

        As to second part:  I need to add more subnets as well as do site-to-client (which google's VPN server doesn't do).

        Currently I'm trying to get it working with a tap interface.

        1 Reply Last reply Reply Quote 0
        • F
          FuriousGeorge
          last edited by

          Sent you PM.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            Well I got in in like 5 minutes

            fired up an instance, wget the openvpn as package

            Boom connected

            gcevpnconnected.png
            gcevpnconnected.png_thumb

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • F
              FuriousGeorge
              last edited by

              I fixed it on my end.

              Set up server for tap.  Set up interface accordingly (needed to reboot as ovpn client was failing to ifconfig).  Set up bridge interface with LAN and OPT1.  Was able to ping vitrual IP of pfSense client from GCE server, but not pfSense's LAN IP or anything behind it.

              did a # sudo ip route add 10.0.0.0/24 dev br0 on server and voila.

              Not sure why it is not working with tun, maybe a bug of some sort with GCE.  Not sure what you did different to get it working on your end.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                I didn't do anything special, installed openvpn as - connected.. using TUN.  I had to change the IP that was in the profile to the external IP..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • F
                  FuriousGeorge
                  last edited by

                  @johnpoz:

                  Well I got in in like 5 minutes

                  fired up an instance, wget the openvpn as package

                  Boom connected

                  I had no problem connecting.  Can you ping pfSense or anything behind its nat, assuming there is NAT.

                  (BTW, I erroneously said there was no NAT on my GCE slice earlier, but now I think it is 1:1 NAT.  I'm new to all this stuff.)

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    I am routing my traffic over the connection..

                    What exactly are you wanting to accomplish with the vpn connection??

                    publicip.png
                    publicip.png_thumb

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • F
                      FuriousGeorge
                      last edited by

                      @johnpoz:

                      I am routing my traffic over the connection..

                      What exactly are you wanting to accomplish with the vpn connection??

                      I have a funny feeling you only breezed through my post :P

                      For now I have accomplished what I wanted to accomplish, which is a site-to-site VPN.

                      Subnets are going to be added from various physical locations with lans behind pfsense and dd-wrt (in most cases).  There will be some modestly intricate routing between them.  In this case, the default gateway is always the local one.

                      On the GCE subnet side some services will service.

                      There will also be client-to-server connections which will do what you are doing.

                      I think I would rather try and run pfSense on GCE.  It appears to be possible and there is some documentation, but it involves making a KVM virtual disk and loading it into a new instance in GCE, and I don't have a spare PC with VT-d needed to build it.

                      See here:  https://gist.github.com/mkhon/0d8867e07c6b325ae228

                      Who can I bribe to make one for me?  Maybe I'll start a new thread later.

                      1 Reply Last reply Reply Quote 0
                      • F
                        FuriousGeorge
                        last edited by

                        By the way:  anyone trying to do what I'm doing should know that windows firewall by default blocks pings from other subnets, android phones and linux servers do not (not sure about iOS).  That might have really screwed me up had I not read it in the tons of time I spent trying and failing to get tun to work.

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          So your going to have multiple machines on gce?  An they are going to use this vpn machine as their gateway to your network?  Can you setup the GCE networking that way for their instances?

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.