Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Access servers on lan

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 4 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RicoR
      Rico LAYER 8 Rebel Alliance
      last edited by

      Show your OpenVPN setting and Firewall Rules via screenshots.

      -Rico

      1 Reply Last reply Reply Quote 0
      • M
        mururoa
        last edited by

        Openvpn-1.png

        Openvpn-2.png

        Openvpn-3.png

        Openvpn-4.png

        Openvpn-5.png

        1 Reply Last reply Reply Quote 0
        • RicoR
          Rico LAYER 8 Rebel Alliance
          last edited by

          The Firewall "OpenVPN" tab matters most because your have problems with incoming traffic there, right?

          -Rico

          1 Reply Last reply Reply Quote 0
          • M
            mururoa
            last edited by

            Just default on that tab :
            Openvpn-6.png

            1 Reply Last reply Reply Quote 0
            • RicoR
              Rico LAYER 8 Rebel Alliance
              last edited by Rico

              Are your clients using pfSense as gateway or are they pointing to any other router?
              If you try to access Windows servers keep in mind that the Windows Firewall blocks any traffic outside of local/known subnets. Disable the Windows firewall for testing on the target side.

              -Rico

              1 Reply Last reply Reply Quote 0
              • M
                mururoa
                last edited by mururoa

                Well, clients are using pfSense as a gateway as far as I understand. I've checked "force all traffic through the tunnel" as you can see.
                I have no problem with windows server at all. The settings seems correct for that part since the clients can access all windows servers and shares.
                Maybe I should say that the pfSense only purpose is OpenVPN server so that outside clients can connect to the lan. No server from the lan use the pfSense server.
                The only problem I have is to access servers on the same lan subnet that the LAN interface of the pfSense. I can't access 192.168.135.0/24 from the clients. Only from the pfSense server. And the pfSense server (.223) is not the gateway for this lan; the gateway is .1.

                1 Reply Last reply Reply Quote 0
                • RicoR
                  Rico LAYER 8 Rebel Alliance
                  last edited by Rico

                  Well your problem is Asymmetric Routing if you use different gateways. Your servers send traffic for 192.168.144.0/24 back to the other .1 gateway.

                  -Rico

                  1 Reply Last reply Reply Quote 0
                  • noplanN
                    noplan
                    last edited by

                    solved ?

                    settings here ?

                    7007117c-6159-40bc-bff8-858a5e815a8c-grafik.png

                    c6b3fc4f-eea0-4f84-aab0-2f849a30c609-grafik.png

                    1 Reply Last reply Reply Quote 0
                    • M
                      mururoa
                      last edited by mururoa

                      Outbound is set to Hybrid Outbound NAT already.
                      And yes, I guess the problem is asymetric routing since the pfSense box is not the gateway of that lan. Just a server that act as OpenVPN server.
                      How can I solve that ?

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        mururoa @mururoa
                        last edited by mururoa

                        Well, well, I found the solution by myself, with a little help from Rico.
                        The solution was to add, while not recommended, the gateway to the LAN interface.
                        So a Gateway was created in Routing/Gateways and assigned to LAN in Interfaces/LAN.
                        And that's it, now I can access all servers on the LAN subnet and all other subnets too.
                        Like :

                        $ nc -vz 192.168.135.93 22
                        Connection to 192.168.135.93 22 port [tcp/ssh] succeeded!
                        $ nc -vz 192.168.135.5 443
                        Connection to 192.168.135.5 443 port [tcp/https] succeeded!
                        $ nc -vz xxx.214.182.129 443
                        Connection to xxx.214.182.129 443 port [tcp/https] succeeded!

                        But I wonder how this pretty common situation is not already documented ??

                        GertjanG 1 Reply Last reply Reply Quote 0
                        • GertjanG
                          Gertjan @mururoa
                          last edited by

                          @mururoa said in Access servers on lan:

                          But I wonder how this pretty common situation is not already documented ??

                          This is not common :

                          @mururoa said in Access servers on lan:

                          the pfSense box is not the gateway of that lan.

                          Common is : pfSense is the router/firewall/OpenVPN server of the LAN(s).

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.