Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Site-to-site VPN not reachable via LAN

    OpenVPN
    2
    6
    778
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sysoict
      last edited by

      Hi!

      I setup a site-to-site openvpn connection between two pfsense routers.

      The client was set with these parameters;
      IPv4 tunnel network; 10.0.8.0/24
      Remote network: 192.168.39.0/24

      Server:
      IPv4 tunnel network; 10.0.8.0/24
      Remote network: 192.168.37.0/24
      Local network: 192.168.39.0/24

      The pfsense in the default gateway on both networks.

      In the diagnostics tab -> ping -> openvpn on the client I can ping 192.168.39.2
      Using the lan interface (also in diagnostics) I dont get a reply. Also the computers in this lan network can not ping 192.168.39.2. A tracert shows that the traffic to 192.168.39.0/24 is routed via the router (192.168.37.2) , so that looks good.

      On the server I can not ping 192.168.37.2

      On both sides I can ping the OpenVPN IP`s on the OpenVPN interface only (10.8.0.1 and 10.8.0.2)

      What am I missing?

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        @sysoict:

        The client was set with these parameters;
        IPv4 tunnel network; 10.0.8.0/24
        Remote network: 192.168.39.0/24

        Server:
        IPv4 tunnel network; 10.0.8.0/24
        Remote network: 192.168.39.0/24
        Local network: 192.168.37.0/24

        The Remote network on client should be set to the servers site local network.
        A typo?

        1 Reply Last reply Reply Quote 0
        • S
          sysoict
          last edited by

          I just corrected my typo, thnx :)

          1 Reply Last reply Reply Quote 0
          • V
            viragomann
            last edited by

            Which device is 192.168.39.2? pfSense or a host in the LAN?

            If it is a computer in the LAN ensure that the system firewall (Windows or whatever) doesn't block access from other subnets. By default Windows firewall blocks such access while it allows access from its own subnet.

            1 Reply Last reply Reply Quote 0
            • S
              sysoict
              last edited by

              192.168.39.2 is the pfsense

              1 Reply Last reply Reply Quote 0
              • S
                sysoict
                last edited by

                I got it sorted. I setup the wrong vpn type (SSL instead of shared key). Now it works fine

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.