Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN Network is not routing via tunnel

    OpenVPN
    4
    23
    1.8k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RicoR
      Rico LAYER 8 Rebel Alliance
      last edited by Rico

      How about Routing on the non working far side?
      Anything in the table for 10.0.11.0/24 ?

      -Rico

      1 Reply Last reply Reply Quote 0
      • C
        Chris-The-Tuner
        last edited by

        I'm not able to check the Server Side on the second tunnel since i'm not running it.
        What should be there ?
        I have a small suspicion that the Server maybe blocks connections from a LAN network...
        Could that be the case ?

        Greetings Chris-The-Tuner
        Yes i'm german, get used to it :)
        Visit my Webpage @ Chris-The-Tuner.de

        1 Reply Last reply Reply Quote 0
        • RicoR
          Rico LAYER 8 Rebel Alliance
          last edited by

          The Server Side need to know your local network and a route set (normally this happens in the OpenVPN Server Config).
          And of course the Server need to accept your Packets by it's Firewall Rules.
          ATM the only thing we know the Server side knows the Route and accept Packets for the tunnel network.

          -Rico

          chpalmerC 1 Reply Last reply Reply Quote 0
          • chpalmerC
            chpalmer @Rico
            last edited by chpalmer

            In your second picture.. You need to add your LAN to the Remote Networks of that site. 10.0.11.0/24

            Ive got this same scenario between a radio station I do work for and my office.

            Triggering snowflakes one by one..
            Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

            1 Reply Last reply Reply Quote 0
            • RicoR
              Rico LAYER 8 Rebel Alliance
              last edited by

              ...this is what I just said right? ;-)

              -Rico

              chpalmerC 1 Reply Last reply Reply Quote 0
              • chpalmerC
                chpalmer @Rico
                last edited by

                @rico

                Missed that. Yep. I hate this laptop.

                Triggering snowflakes one by one..
                Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                chpalmerC 1 Reply Last reply Reply Quote 0
                • chpalmerC
                  chpalmer @chpalmer
                  last edited by

                  @chpalmer

                  Looking again your radio station router should not have its own LAN in the "remote networks" entry..

                  Triggering snowflakes one by one..
                  Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                  1 Reply Last reply Reply Quote 0
                  • C
                    Chris-The-Tuner
                    last edited by

                    Yep that eas the problem.
                    I just mapped the traffic from my LAN to the IP i get from the VPN Server so that i show up as a Single VPN Client and not as a LAN workstation.

                    Works fine now :)

                    Thank you very mutch !

                    Greetings Chris-The-Tuner
                    Yes i'm german, get used to it :)
                    Visit my Webpage @ Chris-The-Tuner.de

                    1 Reply Last reply Reply Quote 0
                    • RicoR
                      Rico LAYER 8 Rebel Alliance
                      last edited by

                      So you do NAT now?
                      That is not ideal but can work in some cases. :-)

                      -Rico

                      1 Reply Last reply Reply Quote 0
                      • C
                        Chris-The-Tuner
                        last edited by

                        The Admin does not want to let traffic from my LAN pass, so thats the only way i have.

                        Sure its not ideal but hey, its getting the job done.

                        Greetings Chris-The-Tuner
                        Yes i'm german, get used to it :)
                        Visit my Webpage @ Chris-The-Tuner.de

                        chpalmerC 1 Reply Last reply Reply Quote 0
                        • chpalmerC
                          chpalmer @Chris-The-Tuner
                          last edited by

                          @chris-the-tuner said in VPN Network is not routing via tunnel:

                          The Admin does not want to let traffic from my LAN pass, so thats the only way i have.

                          Actually a correctly built firewall rule at the radio station only allowing you workstation IP would do the job just as well. In fact if your not accessing you LAN from any of the other sites Id delete the firewall rule on your local router on the OpenVPN tab.

                          Triggering snowflakes one by one..
                          Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                          1 Reply Last reply Reply Quote 0
                          • C
                            Chris-The-Tuner
                            last edited by

                            I do access my home LAN via a Server running on my pfs ;)

                            Greetings Chris-The-Tuner
                            Yes i'm german, get used to it :)
                            Visit my Webpage @ Chris-The-Tuner.de

                            chpalmerC 1 Reply Last reply Reply Quote 0
                            • chpalmerC
                              chpalmer
                              last edited by

                              I believe you could also place your local workstation at an address such as .129 and then use x.x.x.128/30 on the radio station side "remote network" to limit the size of your network their router sees. I have not tried this but there seems no reason it would not work.

                              Triggering snowflakes one by one..
                              Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                              1 Reply Last reply Reply Quote 0
                              • chpalmerC
                                chpalmer @Chris-The-Tuner
                                last edited by

                                @chris-the-tuner said in VPN Network is not routing via tunnel:

                                I do access my home LAN via a Server running on my pfs ;)

                                Then adjust your local OpenVPN rule to the data center server network to your local LAN.

                                Firewall rules are your friend!

                                Triggering snowflakes one by one..
                                Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                                1 Reply Last reply Reply Quote 0
                                • chpalmerC
                                  chpalmer
                                  last edited by

                                  Remember that connections that are initiated by the allowed end are by proxy allowed to return. You do not need special WAN rules to allow return traffic from the web.. right? Same with any interface.

                                  Triggering snowflakes one by one..
                                  Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                                  1 Reply Last reply Reply Quote 0
                                  • C
                                    Chris-The-Tuner
                                    last edited by

                                    I got a Rule that sorts out traffic trying to connect to my LAN from the radio network.
                                    For the rest its fine since i run the other network anyway 😁

                                    Greetings Chris-The-Tuner
                                    Yes i'm german, get used to it :)
                                    Visit my Webpage @ Chris-The-Tuner.de

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.