Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    openvpn shall use local network

    Scheduled Pinned Locked Moved OpenVPN
    22 Posts 4 Posters 2.3k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P Offline
      pooperman
      last edited by

      let us not discuss sense or nonsense, in my case there is a purpose and I am just in hope that we can find a solution without offtopic discussions.

      Layer 2 is not an option, i need to have layer 3

      please forget wifi, we are only talking about cellphone internet via vpn.

      is there no way like bridging vpn network to 192.168.0.* network?
      adding another vpn client in 192.168.0.* network?

      come on guys you are the experts, cant be that there is no way for doing that.

      1 Reply Last reply Reply Quote 0
      • KOMK Offline
        KOM
        last edited by

        I am able to see everything in my network from the vpn phone, but not the other way round?

        If you can see all your LAN clients with VPN on then it's not directing all traffic out the VPN. Is your wifi on the same LAN or is it on a different subnet? If same LAN then pfSense is not involved at all.

        P 1 Reply Last reply Reply Quote 0
        • P Offline
          pooperman
          last edited by

          @KOM said in openvpn shall use local network:

          I am able to see everything in my network from the vpn phone, but not the other way round?

          If you can see all your LAN clients with VPN on then it's not directing all traffic out the VPN. Is your wifi on the same LAN or is it on a different subnet? If same LAN then pfSense is not involved at all.

          it is not about out rather then in.

          phone connects via cell internet via vpn to www.mydoinain.org
          this redirects it to openvpn servers ip address, goes in via open port in pfsense, goes to pfsense dns server, goes to plex server.

          so I am able to see all clients and use the tunnel for ALL communication. inside 192.168.0.* network and www

          but from 192.168.0.* network I cannot see openvpn client.
          therefore I assume it is something like a virtual network or a rule which block it or just missing routing.

          1 Reply Last reply Reply Quote 0
          • P Offline
            pooperman @KOM
            last edited by

            @KOM said in openvpn shall use local network:

            I am able to see everything in my network from the vpn phone, but not the other way round?

            If you can see all your LAN clients with VPN on then it's not directing all traffic out the VPN. Is your wifi on the same LAN or is it on a different subnet? If same LAN then pfSense is not involved at all.

            please forget WIFI, there is no wifi, I am only connected vi cellphone internet

            1 Reply Last reply Reply Quote 0
            • KOMK Offline
              KOM
              last edited by

              OK, all of that info would have been good to know from your very first post.

              So your VPN is in to yourself. What rules do you have on your OpenVPN interface in pfSense? Just the default one that gets created by the OpenVPN Remote Access wizard? Any other packages running like SNort or Suricata? Anything showing as blocked in your firewall log while testing? Are you running a web proxy like squid?

              P 1 Reply Last reply Reply Quote 0
              • P Offline
                pooperman @KOM
                last edited by

                god damn.... found the problem.

                there was a rule missplaced

                it is now working fine!

                1 Reply Last reply Reply Quote 0
                • KOMK Offline
                  KOM
                  last edited by

                  You're welcome.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Offline
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    Your using DLNA, which is how plex finds player from your vpn connection from your phone via your LTE connection... Sorry but no I don't think so..

                    So your you are either doing something else other than what I Linked to, or your mistaken.. Did you setup pimd or the igmp proxy in pfsense for your vpn connection? Is your iphone rooted and you can use tap mode, etc.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                    P 1 Reply Last reply Reply Quote 0
                    • P Offline
                      pooperman @johnpoz
                      last edited by pooperman

                      @johnpoz
                      problem is solved.

                      i excluded some ip addresses in the rules table. so in case someone hacks in, the impact would be low.

                      of course the ip address of the pc was in that rule set xD

                      my bad, but KOM brought me to that point to recheck the rules.
                      by the way, thanks for that buddy

                      iphone is not rooted or else, everything is just pure gui configuration without any special modification

                      1 Reply Last reply Reply Quote 0
                      • KOMK Offline
                        KOM
                        last edited by

                        OK, he's fixed up. Let's call it a day.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.