Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN - connected; can ping FW; no lan access

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 4 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      viragomann
      last edited by

      Is pfSense the default gateway in your LAN?

      Have you add a firewall pass rule to the OpenVPN interface to allow access?

      Do your LAN hosts response to requests from outside their own subnet?
      You may check that on pfSense. Go to Diagnostic > Ping. Try a ping to a LAN device with default settings, then change to source IP to OpenVPN and try again.

      1 Reply Last reply Reply Quote 0
      • F
        franco.g
        last edited by franco.g

        HI vira...

        Thanks for getting back too me. Please view below:

        I saw that I can't ping it form localhost either.

        1. Yes - pfsense is local gateway on LAN
        2. Screenshots for ping requests, and config.

        Screenshot 2019-11-06 at 14.00.16.png
        Screenshot 2019-11-06 at 14.00.46.png
        Screenshot 2019-11-06 at 14.01.13.png
        Screenshot 2019-11-06 at 14.01.53.png
        Screenshot 2019-11-06 at 14.02.32.png

        1 Reply Last reply Reply Quote 0
        • NogBadTheBadN
          NogBadTheBad
          last edited by

          1573041948397-screenshot-2019-11-06-at-14.01.13.png

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          F 1 Reply Last reply Reply Quote 0
          • F
            franco.g @NogBadTheBad
            last edited by franco.g

            @NogBadTheBad
            Yes, we are. It's just for testing and migration purposes. We are replacing 2 old GTA firewalls with pFsense; since the company(GTA) closed down, and there no longer is any support. I did a past setup at a previous employer with pFsense, and OVPN, and some other services which was flawless.

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @franco.g
              last edited by

              @franco-g
              And what's about the gateway question?

              F 1 Reply Last reply Reply Quote 0
              • F
                franco.g @viragomann
                last edited by franco.g

                @viragomann
                Yes, pFsense is the one, and only gateway on the LAN. Currently this is a stand-alone device on a "lab" environment with one pc connected to the network.

                1 Reply Last reply Reply Quote 0
                • V
                  viragomann
                  last edited by

                  So your LAN device doesn't respond if access comes from outside. Check its firewall.

                  F 1 Reply Last reply Reply Quote 1
                  • F
                    franco.g @viragomann
                    last edited by

                    @viragomann

                    I feel like such an idiot. The following rules on the windows machine firewall was disabled: Domain netw; Private netw - but guest/public netw was still enabled. Will remember to put correct parameters in place for the machines.

                    One question - is it acceptable that I can't ping the device from localhost on pFsense?

                    V 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      @franco-g said in OpenVPN - connected; can ping FW; no lan access:

                      is it acceptable that I can't ping the device from localhost on pFsense?

                      Huh? Your trying to ping using the ping gui menu, and selecting localhost as the source? Why would you think that would ping.. You do not nat to the internal networks.. So no it wouldn't work - just use the automatic setting or select the interface for the network the device your trying to ping is on.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      F 1 Reply Last reply Reply Quote 0
                      • V
                        viragomann @franco.g
                        last edited by

                        @franco-g said in OpenVPN - connected; can ping FW; no lan access:

                        One question - is it acceptable that I can't ping the device from localhost on pFsense?

                        That's the default behaviour.
                        localhost is the device itself. So if you select localhost as source the device may respond, but the respond goes to itself and not back to pfSense.

                        1 Reply Last reply Reply Quote 0
                        • F
                          franco.g @johnpoz
                          last edited by

                          @johnpoz
                          Had a moment of weakness. Confused it with pinging TO localhost in terminal. Rookie booboo like we all do at times.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.