Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSec VPN Internal access

    Scheduled Pinned Locked Moved IPsec
    5 Posts 2 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      meluvalli
      last edited by

      Hoping someone can assist.

      I have IPsec VPN setup for my mobile phone.  I have my mobile phone setup for "Always-On" VPN.

      Works great from outside the network.  No issues.  Problem is, with "Always-On" VPN, it's just that..  Always on…  So, when I join my Wifi (From internal), it VPN's just fine, can ping external IP's like 8.8.8.8, but can't ping internal IP's.  Any clue what would cause this and how to fix this?

      Again, works fine if I'm external.  Can ping my internal clients without a problem.  It's only when I VPN from internal.

      Thanks!

      1 Reply Last reply Reply Quote 0
      • M
        malvank
        last edited by

        what do you see in the logs if you debug the connection?

        1 Reply Last reply Reply Quote 0
        • M
          meluvalli
          last edited by

          @BlueKobold:

          So, when I join my Wifi (From internal)

          So if you are using it from internal or the LAN side you will need to set up something like NAT redirection
          or also called Hairpin NAT, then it will be just running as excepted.

          Never heard of Hairpin NAT :(.

          If you are referring to NAT Reflection, I already have that enabled and set for NAT+PROXY.  Otherwise, if that's not what you are referring to, can you point me in the right direction to setup NAT Redirection/Hairpin NAT?

          Thank you!

          1 Reply Last reply Reply Quote 0
          • M
            meluvalli
            last edited by

            @BlueKobold:

            If this will not help oyu out then you should better disable at home the VPN part if you are
            connecting to your home network internally.

            I followed the directions from: https://doc.pfsense.org/index.php/Why_can't_I_access_forwarded_ports_on_my_WAN_IP_from_my_LAN/OPTx_networks, however, this isn't my problem.  So NAT Redirection isn't the problem here (at least I don't think)….  I can't even ping my internal IP's by IP number...

            1 Reply Last reply Reply Quote 0
            • M
              meluvalli
              last edited by

              @BlueKobold:

              If this will not help oyu out then you should better disable at home the VPN part if you are
              connecting to your home network internally.

              Really?  So because I didn't understand what you were talking about, you quit helping??  How RUDE!!!!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.