Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [SOLVED] Unable to reach pfsense or any computer on its subnet from VPN server

    Scheduled Pinned Locked Moved OpenVPN
    18 Posts 2 Posters 4.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      FuriousGeorge
      last edited by

      @johnpoz:

      And where do they state that is supported??

      Your going to have to put a public IP on your instance that is running, not some port forward..

      I don't want to assume it isn't.

      @johnpoz:

      What is it that you need btw??  Can I fire up a google compute instance for low cost or free for testing?

      No but I can make one for you.

      @johnpoz:

      I see they have a $300 60 day free trial, signing up..  So what is it exactly your wanting to accomplish?

      That's for support.  An instance might only cost you $5 per month if you get the teeny tiny one.

      As to second part:  I need to add more subnets as well as do site-to-client (which google's VPN server doesn't do).

      Currently I'm trying to get it working with a tap interface.

      1 Reply Last reply Reply Quote 0
      • F
        FuriousGeorge
        last edited by

        Sent you PM.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Well I got in in like 5 minutes

          fired up an instance, wget the openvpn as package

          Boom connected

          gcevpnconnected.png
          gcevpnconnected.png_thumb

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • F
            FuriousGeorge
            last edited by

            I fixed it on my end.

            Set up server for tap.  Set up interface accordingly (needed to reboot as ovpn client was failing to ifconfig).  Set up bridge interface with LAN and OPT1.  Was able to ping vitrual IP of pfSense client from GCE server, but not pfSense's LAN IP or anything behind it.

            did a # sudo ip route add 10.0.0.0/24 dev br0 on server and voila.

            Not sure why it is not working with tun, maybe a bug of some sort with GCE.  Not sure what you did different to get it working on your end.

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              I didn't do anything special, installed openvpn as - connected.. using TUN.  I had to change the IP that was in the profile to the external IP..

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • F
                FuriousGeorge
                last edited by

                @johnpoz:

                Well I got in in like 5 minutes

                fired up an instance, wget the openvpn as package

                Boom connected

                I had no problem connecting.  Can you ping pfSense or anything behind its nat, assuming there is NAT.

                (BTW, I erroneously said there was no NAT on my GCE slice earlier, but now I think it is 1:1 NAT.  I'm new to all this stuff.)

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  I am routing my traffic over the connection..

                  What exactly are you wanting to accomplish with the vpn connection??

                  publicip.png
                  publicip.png_thumb

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • F
                    FuriousGeorge
                    last edited by

                    @johnpoz:

                    I am routing my traffic over the connection..

                    What exactly are you wanting to accomplish with the vpn connection??

                    I have a funny feeling you only breezed through my post :P

                    For now I have accomplished what I wanted to accomplish, which is a site-to-site VPN.

                    Subnets are going to be added from various physical locations with lans behind pfsense and dd-wrt (in most cases).  There will be some modestly intricate routing between them.  In this case, the default gateway is always the local one.

                    On the GCE subnet side some services will service.

                    There will also be client-to-server connections which will do what you are doing.

                    I think I would rather try and run pfSense on GCE.  It appears to be possible and there is some documentation, but it involves making a KVM virtual disk and loading it into a new instance in GCE, and I don't have a spare PC with VT-d needed to build it.

                    See here:  https://gist.github.com/mkhon/0d8867e07c6b325ae228

                    Who can I bribe to make one for me?  Maybe I'll start a new thread later.

                    1 Reply Last reply Reply Quote 0
                    • F
                      FuriousGeorge
                      last edited by

                      By the way:  anyone trying to do what I'm doing should know that windows firewall by default blocks pings from other subnets, android phones and linux servers do not (not sure about iOS).  That might have really screwed me up had I not read it in the tons of time I spent trying and failing to get tun to work.

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        So your going to have multiple machines on gce?  An they are going to use this vpn machine as their gateway to your network?  Can you setup the GCE networking that way for their instances?

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.