Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Access servers on lan

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 4 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mururoa
      last edited by

      Openvpn-1.png

      Openvpn-2.png

      Openvpn-3.png

      Openvpn-4.png

      Openvpn-5.png

      1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by

        The Firewall "OpenVPN" tab matters most because your have problems with incoming traffic there, right?

        -Rico

        1 Reply Last reply Reply Quote 0
        • M
          mururoa
          last edited by

          Just default on that tab :
          Openvpn-6.png

          1 Reply Last reply Reply Quote 0
          • RicoR
            Rico LAYER 8 Rebel Alliance
            last edited by Rico

            Are your clients using pfSense as gateway or are they pointing to any other router?
            If you try to access Windows servers keep in mind that the Windows Firewall blocks any traffic outside of local/known subnets. Disable the Windows firewall for testing on the target side.

            -Rico

            1 Reply Last reply Reply Quote 0
            • M
              mururoa
              last edited by mururoa

              Well, clients are using pfSense as a gateway as far as I understand. I've checked "force all traffic through the tunnel" as you can see.
              I have no problem with windows server at all. The settings seems correct for that part since the clients can access all windows servers and shares.
              Maybe I should say that the pfSense only purpose is OpenVPN server so that outside clients can connect to the lan. No server from the lan use the pfSense server.
              The only problem I have is to access servers on the same lan subnet that the LAN interface of the pfSense. I can't access 192.168.135.0/24 from the clients. Only from the pfSense server. And the pfSense server (.223) is not the gateway for this lan; the gateway is .1.

              1 Reply Last reply Reply Quote 0
              • RicoR
                Rico LAYER 8 Rebel Alliance
                last edited by Rico

                Well your problem is Asymmetric Routing if you use different gateways. Your servers send traffic for 192.168.144.0/24 back to the other .1 gateway.

                -Rico

                1 Reply Last reply Reply Quote 0
                • noplanN
                  noplan
                  last edited by

                  solved ?

                  settings here ?

                  7007117c-6159-40bc-bff8-858a5e815a8c-grafik.png

                  c6b3fc4f-eea0-4f84-aab0-2f849a30c609-grafik.png

                  1 Reply Last reply Reply Quote 0
                  • M
                    mururoa
                    last edited by mururoa

                    Outbound is set to Hybrid Outbound NAT already.
                    And yes, I guess the problem is asymetric routing since the pfSense box is not the gateway of that lan. Just a server that act as OpenVPN server.
                    How can I solve that ?

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      mururoa @mururoa
                      last edited by mururoa

                      Well, well, I found the solution by myself, with a little help from Rico.
                      The solution was to add, while not recommended, the gateway to the LAN interface.
                      So a Gateway was created in Routing/Gateways and assigned to LAN in Interfaces/LAN.
                      And that's it, now I can access all servers on the LAN subnet and all other subnets too.
                      Like :

                      $ nc -vz 192.168.135.93 22
                      Connection to 192.168.135.93 22 port [tcp/ssh] succeeded!
                      $ nc -vz 192.168.135.5 443
                      Connection to 192.168.135.5 443 port [tcp/https] succeeded!
                      $ nc -vz xxx.214.182.129 443
                      Connection to xxx.214.182.129 443 port [tcp/https] succeeded!

                      But I wonder how this pretty common situation is not already documented ??

                      GertjanG 1 Reply Last reply Reply Quote 0
                      • GertjanG
                        Gertjan @mururoa
                        last edited by

                        @mururoa said in Access servers on lan:

                        But I wonder how this pretty common situation is not already documented ??

                        This is not common :

                        @mururoa said in Access servers on lan:

                        the pfSense box is not the gateway of that lan.

                        Common is : pfSense is the router/firewall/OpenVPN server of the LAN(s).

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.