Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiple open vpn server routing help

    Scheduled Pinned Locked Moved OpenVPN
    15 Posts 2 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Mat1987
      last edited by

      I dont have remote networks from a client server setup.

      on my other pfsense box (Remote) i have put remote networks.

      i used the client export for the vpn client access.  its connects fine and i can ping my main router ip but not the 192.168.0.0 or 192.168.1.0

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        The point is if you can access 192.168.0.0/24 from 192.168.50.0.

        1 Reply Last reply Reply Quote 0
        • M
          Mat1987
          last edited by

          From my local network 192.168.50.0 to 192.168.0.0 or 192.168.1.0 i get access.

          from a vpn client i can access 192.168.50.0 but not 192.168.0.0 or 192.168.1.0

          Mat

          1 Reply Last reply Reply Quote 0
          • V
            viragomann
            last edited by

            So it seems the route to the clienst tunnel subnet is missing on the remote site.
            If you have access to this vpn server, you can add it, otherwise you can do a workaround via NAT.

            1 Reply Last reply Reply Quote 0
            • M
              Mat1987
              last edited by

              I do have access to the remote site and on the remote site the local ip addresses in so still puzzled

              1 Reply Last reply Reply Quote 0
              • V
                viragomann
                last edited by

                So if you look in the routing table of the remote site router you can see an entry for the clients tunnel subnet 192.168.61.0/24 pointing to the clients address?

                If this is given check the rules. The assess must be allowed at the vpn server in the main subnet and on the remote site.
                Try to ping the remote site router itself from the client.

                1 Reply Last reply Reply Quote 0
                • M
                  Mat1987
                  last edited by

                  @viragomann:

                  So if you look in the routing table of the remote site router you can see an entry for the clients tunnel subnet 192.168.61.0/24 pointing to the clients address?

                  If this is given check the rules. The assess must be allowed at the vpn server in the main subnet and on the remote site.
                  Try to ping the remote site router itself from the client.

                  From the client i cant ping the remote site router.

                  Remote.PNG
                  Remote.PNG_thumb

                  1 Reply Last reply Reply Quote 0
                  • M
                    Mat1987
                    last edited by

                    Main Site

                    MainSite.PNG
                    MainSite.PNG_thumb

                    1 Reply Last reply Reply Quote 0
                    • V
                      viragomann
                      last edited by

                      I can't see a route to the openvpn2 clients tunnel network at remote site.
                      So you'll have to add 192.168.61.0/24 to the "Remote Networks" in server config at remote site.

                      @Mat1987:

                      From the client i cant ping the remote site router.

                      However, this way this ping shouldn't work also as long, as.

                      Since the remote networks have broadly used subnets (192.168.0.0/24 and 192.168.1.0/24) also ensure that your client isn't within one of theese subnets.

                      Edit:
                      To "Remote Networks" of course!. I shouldn't hand out advices after drinking beers.  ::)

                      1 Reply Last reply Reply Quote 0
                      • M
                        Mat1987
                        last edited by

                        Ok i have added this

                        192.168.50.0/24,192.168.1.0/24,192.168.0.0/24,192.168.60.0/24,192.168.61.0/24

                        You are a legend.  How stupid do i feel.  yes adding the tunnel networks to the remote networks allows connection.

                        Thanks so much.  i suppose learning never hurt anyone :)

                        Mat

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.