Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Site to site OpenVPN with destination set to Remote Access (SSL/TLS)?

    Scheduled Pinned Locked Moved OpenVPN
    7 Posts 3 Posters 852 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • iorxI
      iorx
      last edited by

      Site to site OpenVPN with server set to Remote Access (SSL/TLS)?

      Is this possible?
      I've tried it but have trouble passing traffic from the remote LAN to the Local LAN.

      The underlying reason for this is that I only got (out of my control) one port open into to the OpenVPN server. I need both user and this site to site solution working on one port in.

      Peer to Peer (SSL/TLS) work fine if I do that way, but then I can't have clients.

      Brgs,

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        You need to set up a Client Specific Override on the server for the remote client to route packets destined for the remote LAN over the VPN.
        In the CSO settings enter the remote LAN network in the "Remote networks" box.

        1 Reply Last reply Reply Quote 0
        • iorxI
          iorx
          last edited by

          Yes, I had that CSO in place, same override I had working for peer to peer. Still didn't manage to get remote LAN traffic to pass. pfSense though could reach server side LAN addresses.
          Strange. Got to give it another try.

          1 Reply Last reply Reply Quote 0
          • V
            viragomann
            last edited by

            Is the remote pfSense the default gateway in its LAN?

            Are the routes okay on both sites?

            1 Reply Last reply Reply Quote 0
            • iorxI
              iorx
              last edited by

              Yes, hosts on the remote LAN got gw to the pfsense.

              Routes on the remote pfsense also looks good. The subnet for the servers LAN and tunnel-net is present. Routes on the server side also looks like they should.

              I need to go through this thoroughly and see if I've missed something. Strange thing is that peer to peer (SSL/TLS) went up directly.

              As it should work with Remote Access I have to look for some stupid mistake somewhere.

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                It can work though you may need to manage some things manually, for example the IPv4 Remote Networks (and IPv6 Remote Networks) boxes are hidden in Remote Access mode, so you'd have to add route statements for the equivalent set of networks in the advanced/custom options box.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • iorxI
                  iorx
                  last edited by

                  Yeah! I was missing those. Had an idea that CSO should be enough.

                  Gave it a try.

                  server pfsense:

                  • Config: Remote Access
                  • added route statement for the remote subnet in custom options
                  • local networks: local subnet, remote subnet
                    (peer to peer server should have this, still trying to figure out why the remote subnet should be here, but according the pf-guide-doc it should, and it works as intended)
                  • CSO: remote networks: remote subnet
                    Question here: In the CSO i got a Local Network field. Does this have effect on this kind of config?

                  remote pfsense:

                  • Config: Peer to peer
                  • tunnel network: empty
                  • remote network: empty (in peer to peer config these are configured at time of connect, true for this scenario too?)

                  But, no, can't pass traffic LAN to LAN.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.