Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Windows File/Printer sharing on OpenVPN

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 2 Posters 5.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      agismaniax
      last edited by

      I have several RoadWarrior client with IP 172.16.100.0/24.
      My LAN is 172.16.4.0/16 and the pfsense box is 172.16.4.252/16.

      I can see windows file/printer sharing from RoadWarrior client to LAN client, but I can't reach file/printer sharing from LAN to RoadWarrior client. I'm using IP address instead of computer's name.
      Ping is fine from both side. I only have one firewall LAN default rules activated.

      Should I add more firewall rules?

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        To be honest i'm surprised you can ping at all since you use a /16 for your lan and a /24 within that /16 for you RoadWarriors.

        Most probably it's a problem with the client (Win XP?) and not with pfSense.
        Try to disable the WindowsFirewall and see if that helps.
        After that enable it again and find out what to allow.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • A
          agismaniax
          last edited by

          oh… you're right... i turn off windows firewall and i can access all file/printer sharing...  ;D

          btw... i have 3 pfsense box, the default gw for LAN is 172.16.4.254.
          the OpenVPN is in another pfsense box using additional static route at the client/server on LAN.

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            why not just use a different subnet?
            i mean it makes it only more complicated and could be a source of problems.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • A
              agismaniax
              last edited by

              hmmm… nice suggestion... i think i will shrink the subnet on LAN from /16 to /24 or using different ip block for openvpn.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.