Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN Client cannot access some IP addresses

    Scheduled Pinned Locked Moved OpenVPN
    14 Posts 4 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      ianllew600 @hugoeyng
      last edited by

      @hugoeyng hi, it's not a problem with clients connecting, they can all connect to the vpn server fine. The issue is reaching resources within the lan through the vpn. I can connect to some servers but can not connect to others.

      I think this may have something to do with the pfsense firewall but the rules look OK to me.

      hugoeyngH 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by johnpoz

        @ianllew600 said in VPN Client cannot access some IP addresses:

        I think this may have something to do with the pfsense firewall

        And why the firewall allow access to X but block to Y... Makes no sense when you have a any any rule.

        What makes sense is the device your trying to talk to that is not working is running a firewall, or he doesn't point back to pfsense as his gateway..

        Windows for example out of the box firewall would block access to anything that is not its local network, ie your vpn client coming from your tunnel network IP.

        Simple test, sniff on pfsense lan interface when your client tries to talk to one of these IPs on your lan not working.. Do you see pfsense send this traffic on? If so then its not pfsense.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        I 1 Reply Last reply Reply Quote 0
        • I
          ianllew600 @johnpoz
          last edited by

          @johnpoz thanks for the reply ut makes sense to me what you are saying, the device I'm trying to connect to is an unraid server which doesn't gave a firewall that I can find so it can it be blocking it.

          1 Reply Last reply Reply Quote 0
          • S
            serbus
            last edited by

            Hello!

            Are you running the pfB DNSBL webserver on the default VIP (10.10.10.1)?

            John

            Lex parsimoniae

            I 1 Reply Last reply Reply Quote 1
            • I
              ianllew600 @serbus
              last edited by

              @serbus hi its a new install and haven't got any pfblocking installed yet, I'm at a loss.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by johnpoz

                Again do the simple sniff test.. Filter it on the IP address of your unraid box.

                You sure you have the correct IP for this unraid box? Is the unraid box pointing back to pfsense as its gateway?

                Your rule is any any.. there is zero reason pfsense would block access 192.168.1.X while allowing access to 192.168.1.Y

                What is the IP address of your client local network, what is the tunnel network? What is the IP address your using on your lan, and what is the IP of your unraid box. What is the mask of the unraid box? If it thinks the source IP your coming from is on its own network, then it would never send traffic back to pfsense.

                Can pfsense talk to this unraid IP? Can you ping it from pfsense? You have validated that is the correct mac address for the unraid nic?

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • hugoeyngH
                  hugoeyng @ianllew600
                  last edited by

                  @ianllew600 I wunderstood and it happens to me too. There are three servers in my office and we use OpenVPN to home office . I am able to access two servers but not the third one. The servers are pluged on the same router and the same IP range.

                  To manage this question I connect one server and then, connect to the one I can´t connect trought OpenVPN. This is not, obviously, a solution.

                  I love pfSense!

                  Hugo Eyng
                  Datamais Sistemas

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    If you can access box A on your lan, but not box B on the same lan.. And your not filtering in your openvpn rules.. Then the problem is with Box B, not pfsense..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    hugoeyngH 1 Reply Last reply Reply Quote 0
                    • hugoeyngH
                      hugoeyng @johnpoz
                      last edited by

                      @johnpoz I agree. But what?

                      I love pfSense!

                      Hugo Eyng
                      Datamais Sistemas

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by johnpoz

                        Still waiting for the OP to actually provide some info to help prove that too him, like a simple 10 second sniff while he its trying to access said IP, etc.

                        Your issue with the 3rd server is same.. Its something on the server, wrong mask, no gateway, firewall, etc..

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • I
                          ianllew600
                          last edited by ianllew600

                          Hi everyone,

                          Just wanted to say a massive thanks to everyone for the help! I was going round and round in circles until you guys put me back on the right track.

                          So i found the issue and it was indeed with the server, it would seem that someone had setup a network connection that wasn't on the diagrams with a static IP that was the same as we used for the openvpn server (10.10.10.0/24). Once i found this i changed the openvpn server address (10.10.11.0/24) and now everything works. It would seem that the server was sending the reply out of the wrong NIC and it was never getting back to PFSENSE, the reason it worked on the other servers was because they didn't have this static ip set on a nic.

                          What a nightmare... but working now.

                          Thanks again.

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            Yeah.. That would do it! Glad you got it sorted.

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.