OpenVPN on dual WAN - cannot reach clients
-
Hi folks,
got a problem with OpenVPN. Hope somebody can point me into the right direction.
I have pfsense 2.2.4 setup with Dual WAN (2 seperate providers) for failover and loadbalance. That is working great.
I also have setup OpenVPN, and I can connect and establish a connection on both WAN connections.
OpenVPN setup for "Interface" is "localhost".
Than I forward the UDP connection on each WAN to "localhost or 127.0.0.1".
This was the only way I could get OpenVPN setup to work on both WAN interfaces and this is the recommended setup here on the forum.Now, I can ping the pfsense box (172.24.0.1) no problem, but, I cannot ping any other clients. I am trying to get RDP working, but a simple ping does also not work.
What am I missing?
Thanks.
-
probably firewall rules or routes or both.
-
Hope the attached pictures help.
![VPN Interface.PNG](/public/imported_attachments/1/VPN Interface.PNG)
![VPN Interface.PNG_thumb](/public/imported_attachments/1/VPN Interface.PNG_thumb)
-
Anybody?
-
rules seem ok
must be routes then … show pics of the vpn config for more insight pls
-
I hope the pictures help. I dont know howto get the text version of the OpenVPN Server config.
If you can tell me where to find it, I can upload that as well.
-
you don't need to push your tunnel network, you need to push you lan network
-
I removed the push to Tunnel network and added:
push "route 172.24.0.0 255.255.0.0";
But it did not solve my problem.
It seems to me, that the Tunnel is going to localhost, but is stuck there and cannot reach the LAN. I can connect via VPN on both WAN interfaces and access the pfsense box web interface and access the internet, but not the LAN.
-
do the routes show up in the routing tables on the clients ?
-
How can I check that?
-
-
see picture of routing table.
As far as I can tell, the route does show up properly.
![Routing Table.PNG](/public/imported_attachments/1/Routing Table.PNG)
![Routing Table.PNG_thumb](/public/imported_attachments/1/Routing Table.PNG_thumb) -
yes but you are having a route for 2 subnets ??
a /16 one and a /24 both pointing towards 172.24.0.0 …. why is that ?
-
Hi,
I noticed that as well and removed it already. It was, because of the push entry that was pointing to /16. i changed it to /24. Now it only shows one route to 172.24.0.0 /24.
-
Hi,
anybody have any further ideas? This is still not working, but I cannot find the issue. All settings look fine.