Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    I think it is not difficult issue but i have really no idea ..

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 3 Posters 687 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G Offline
      goethepieng
      last edited by

      Dear All,

      it is really stupid question i think  which i ask but no idea since one week.

      openvpn setting
      my IPv4 Tunnel Network 192.168.2.0/24
      my IPv4 Local network(s) is 10.71.2.0/24 -> also my local office LAN

      my pfsense server lan IP is 10.71.2.254

      all setup ok and clients can connect w/o issue but issue is when in the LAN network server w/o setup a default gateway to our pfsense server
      the openvpn client cannot access this server at all.
      when server has setup the default gateway to our pfsense server then is ok.

      ex.
      clients can connect 10.71.2.1  -> server default GW is 10.71.2.254 then is work
      clients can connect 10.71.2.7  -> server default GW is blank, cause it has two LAN card and default GW is WAN IP GW

      i google it but really no successful answer which i can use so i ask all profi users in forum now.
      i hope someone can help me it will be really great.

      Best Regards,
      Arno

      1 Reply Last reply Reply Quote 0
      • JKnottJ Offline
        JKnott
        last edited by

        my IPv4 Local network(s) is 10.71.2.0/24 -> also my local office LAN

        That's your problem, they have to be different.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator
          last edited by

          Help you with what exactly?

          Your trying to access a server thats gateway is not back to pfsense where the vpn tunnel is.. So you want to fix that?

          You have 2 options, well 3 really.
          1st would be to use pfsense as your gateway.
          2nd would be to source nat your vpn connections so that clients see the traffic from vpn clients as IP address of pfsense on that network of the server..
          3rd create host route on the server telling it that to get to your tunnel network talk to pfsense.

          This is actually a bit confusing.
          "my IPv4 Local network(s) is 10.71.2.0/24 -> also my local office LAN"

          Are you saying your remote vpn client is on same network address space as the LAN your trying to go down the vpn to get to?  Yeah that is broken setup.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • G Offline
            goethepieng
            last edited by

            Dear John,

            yes. it is what i want to fix.
            the setting is like attached and i just want to connect my office network 10.71.2.0 thru VPN tunnel . now i can only connect server which GW is back to pfsense like you wrote

            but what is detail option 2 you mean and how to setup it?

            2nd would be to source nat your vpn connections so that clients see the traffic from vpn clients as IP address of pfsense on that network of the server..

            thanks

            BR
            Arno

            open.JPG
            open.JPG_thumb

            1 Reply Last reply Reply Quote 0
            • johnpozJ Offline
              johnpoz LAYER 8 Global Moderator
              last edited by

              On your outbound nat pick the interface for the network these servers are on, and nat traffic using pfsense interface IP.. Its just like any other outbound nat, but into your lan..

              I have gone over source nat multiple times in other posts.. Find one of those..

              edit:  here is a recent thread where showing doing a source nat
              https://forum.pfsense.org/index.php?topic=137152.0

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.