Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Open VPN Only Working One Way

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 3 Posters 2.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      WJWB
      last edited by

      Used the guide specified here:

      https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/configuring-a-site-to-site-static-key-openvpn-instance.html

      Tunnel is up and working, pinging from the client pfsense to the lan on the side of the pfsense openvpn server but not vise versa and not from the client side lan :(

      1 Reply Last reply Reply Quote 0
      • chpalmerC
        chpalmer
        last edited by chpalmer

        Either your "remote network" on site one is wrong or your "OpenVPN" firewall rule on site two is wrong.

        Show screenshots of each of those.

        I've tried adding a gateway on the tunnel network, and adding static route to site 2 but this hasn't made a difference.

        You should not have to do either of those. In fact Id delete them before you troubleshoot further.

        I can't ping from another machine on site 2 to an address on site1
        Can you ping from that same machine to the site 1 pfsense LAN interface?

        Also remember- Windows machines will treat any "out of subnet" address as pubic and block with its own firewall.

        Triggering snowflakes one by one..
        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

        W 1 Reply Last reply Reply Quote 0
        • W
          WJWB @chpalmer
          last edited by

          @chpalmer

          I removed the gateway and static route after they didn't work

          Below Site 1 Open VPN Settings

          b00fbb4d-0906-43a9-a06e-39097ab1568f-image.png

          Below is Site 2 Firewall Rules

          d4a76265-389a-44ca-adbc-190bf0184d69-image.png

          Windows firewall is disabled on the PC I'm using to test.

          1 Reply Last reply Reply Quote 0
          • chpalmerC
            chpalmer
            last edited by chpalmer

            Look at /Diagnostics /Routes and see if the opposite LAN is there..

            /diag_routes.php

            Next Id pull up the configs and compare them side by side.. Im trying to remember which settings could be a little different and cause such an issue. Seems to me anything I ever had issues with blocked my efforts both directions.

            I assume your LAN rules are all default? There is no traffic that has hit that rule you have the screenshot of above.. Look at your firewall logs. Do you see any blocked traffic when you try to ping or otherwise?

            Are you behind a dsl modem on either side of this connection??

            Triggering snowflakes one by one..
            Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

            W 1 Reply Last reply Reply Quote 0
            • KOMK
              KOM
              last edited by

              You also have all your local networks defined on each end?

              1 Reply Last reply Reply Quote 0
              • W
                WJWB @chpalmer
                last edited by

                @chpalmer

                Look at /Diagnostics /Routes and see if the opposite LAN is there..

                Yes It's there:
                3376bff0-2d49-4835-860c-f20029e1f689-image.png

                Next Id pull up the configs and compare them side by side.. Im trying to remember which settings could be a little different and cause such an issue. Seems to me anything I ever had issues with blocked my efforts both directions.

                I agree, I can't understand why it works one way but not the other =(

                I assume your LAN rules are all default? There is no traffic that has hit that rule you have the screenshot of above.. Look at your firewall logs. Do you see any blocked traffic when you try to ping or otherwise?

                Your assumption is correct

                Are you behind a dsl modem on either side of this connection??

                Yes Site 2 is behind a DSL Modem and pfsense is another device on the network there is a static route on the DSL modem to route 172.16.28.0/24 to the pfsense ip. I've also tried using the pfsense box as the default gateway on devices on the Site 1 Network

                @KOM

                The Interface is configured, I would assume the network is also as it appears in the above route table.

                1 Reply Last reply Reply Quote 0
                • chpalmerC
                  chpalmer
                  last edited by

                  I ask about the DSL modem because I did have one "gateway" model that was somehow screwing with traffic in a similar fashion. Once I rebooted that device the issues stopped. It was Centurylink and was not a Technicolor model. I do not remember the exact model though.

                  Could you possibly put yours in bridge mode and let your pfsense WAN do the pppoe?

                  Triggering snowflakes one by one..
                  Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                  W 1 Reply Last reply Reply Quote 0
                  • W
                    WJWB @chpalmer
                    last edited by

                    @chpalmer It's an option at the moment the device runing pfsense only has one NIC. I've tried with a VM with 2 Nics but getting the same. Frustrating

                    1 Reply Last reply Reply Quote 0
                    • chpalmerC
                      chpalmer
                      last edited by

                      I would try that box on a different internet connection to rule that out.

                      Triggering snowflakes one by one..
                      Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                      1 Reply Last reply Reply Quote 0
                      • W
                        WJWB
                        last edited by

                        It appears that was the issue having only one NIC, a box with 2 NICs on different submets connects and pings fine but now I've ran into the problem that it doesn't have a great throughput tried both OpenVPN and IPSec but packets over 50kb fail on pings.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.