Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Access Webconfigurator on standby firewall's LAN interface from OpenVPN Client

    Scheduled Pinned Locked Moved OpenVPN
    3 Posts 2 Posters 438 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • HerticWildH Offline
      HerticWild
      last edited by

      We want to disable external Webconfigurator access to our firewalls.
      Before we can do that, we have to be able to connect to the Webconfigurator via the LAN interfaces of both servers.
      We have OpenVPN configured to use a CARP IP.
      We are using HASync to keep the 2 firewalls the same (FW1, FW2).
      We can connect to the GUI via FW1's lan interface but we can not connect to the standby via it's LAN interface. We can only access the GUI via the WAN.
      I think it's a routing issue as the firewall rules are in place to allow OpenVPN clients GUI access. When I look at the routes, the only difference I see is on the one currently running OpenVPN (FW1):

      Dest 192.168.1.0/24
      GW 192.168.1.2
      Flag UGS
      Use 1752640
      MTU 1500
      Netif ovpns2

      Dest 192.168.1.2
      GW link#16
      Flag UH
      USE 644803
      MTU 1500
      Netif ovpns2

      Those 2 routes.

      Do I need to add a static route on FW1 from the OpenVPN client network to the LAN interface of FW2?

      If I do that - what happens when FW1 goes away, and OpenVPN starts running on FW2?

      Or is there a better way to achieve this?

      1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann
        last edited by

        A solution for that is described here under "You cannot reach the slave pfSense via OpenVPN":
        https://vorkbaard.nl/openvpn-in-a-pfsense-carp-cluster

        HerticWildH 1 Reply Last reply Reply Quote 2
        • HerticWildH Offline
          HerticWild @viragomann
          last edited by

          @viragomann
          Worked like a charm - thanks!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.