Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN Remote acces server on VPS without LAN

    Scheduled Pinned Locked Moved OpenVPN
    2 Posts 2 Posters 519 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      hyposera
      last edited by hyposera

      Hi there!
      I would like to set up the pfsense openvpn remote access server on VPS and connect my local pfsense box as a client. The issue is that remote VPS has only WAN interface. Is it the issuse in general (i mean, setting up the pfsense openvpn remote access server with 1 interface)? I've tried to create vpn server with wizard. But im not sure that i have done it well because i can connect to the server but can;t acces to the internet in this case. Which firewall rules, NAT rules are needed on pfsense to route all my local pfsense traffic through remote VPS machine?

      I hope somebody can help me.
      Thank you a lot in advance!

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        The wizard sets the firewall rules automatically which are needed to access the server and also for anything else over the VPN.

        What you have to check is the "Redirect gateway" check in the server settings. But I think, this is set by the wizard as well.

        @hyposera said in OpenVPN Remote acces server on VPS without LAN:

        I would like to set up the pfsense openvpn remote access server on VPS and connect my local pfsense box as a client.

        I assume, you aim to direct any upstream traffic from the network behind your local box over the VPN.
        So you have to add an outbound NAT rule for that traffic. If your outbound NAT works in automatic mode switch to hybrid mode and save that setting.
        Add a rule like this:
        interface: OpenVPN
        source: any (or restict it to your LANs)
        destination: any
        Translation: interface address

        I assume, you're running only that one OpenVPN instance (client or server) here. If you run multiple, assign an interface to the client instance and use that one in the NAT rule.

        On the remote pfSense, you also to add an outbound NAT rule like the above one, but to the WAN interface.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.