Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    4 pfsense servers+vpn routing+vpn gui client

    Scheduled Pinned Locked Moved OpenVPN
    16 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • KOMK
      KOM @Rostyslav Didus
      last edited by

      @rostyslav-didus OK that looks good. It's not every day I see someone using a /23.

      What are your firewall rules for the OpenVPN interfaces?

      Rostyslav DidusR 1 Reply Last reply Reply Quote 0
      • Rostyslav DidusR
        Rostyslav Didus @KOM
        last edited by

        @kom
        We've got many clients )
        Screenshot_13.png

        KOMK V 2 Replies Last reply Reply Quote 0
        • KOMK
          KOM @Rostyslav Didus
          last edited by KOM

          This post is deleted!
          1 Reply Last reply Reply Quote 0
          • V
            viragomann @Rostyslav Didus
            last edited by

            @rostyslav-didus
            Maybe the destination devices are blocking access from outside their local networks. This is the default behavior of PC firealls.

            Rostyslav DidusR 1 Reply Last reply Reply Quote 0
            • KOMK
              KOM
              last edited by

              Dammit, clicked Delete by accident...

              viragomann had a good suggestion above. Often times a desktop firewall will block traffic from outside its local subnet.

              Can you not access anything on any network, or are you just trying Windows systems?

              Rostyslav DidusR 1 Reply Last reply Reply Quote 0
              • Rostyslav DidusR
                Rostyslav Didus @KOM
                last edited by

                @kom I saw that message )
                It is about vpn's config on each server.I'll add this info tomorrow.

                1 Reply Last reply Reply Quote 0
                • Rostyslav DidusR
                  Rostyslav Didus @viragomann
                  last edited by

                  @viragomann
                  I wish it was like this way.
                  But it is not.Windows FIrewall is turned off.
                  For some reason pfsense allows me to see only network behind the server I connected to.I'll add vpn config's of all servers tomorrow.
                  Thank you.

                  V 1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @Rostyslav Didus
                    last edited by

                    @rostyslav-didus said in 4 pfsense servers+vpn routing+vpn gui client:

                    For some reason pfsense allows me to see only network behind the server I connected to.

                    From your first post, I assumed you get not even this.

                    So you connect to different servers by vpn and want to access the remote networks in the other locations, which are connected with a site2site?

                    Rostyslav DidusR 1 Reply Last reply Reply Quote 0
                    • Rostyslav DidusR
                      Rostyslav Didus @viragomann
                      last edited by

                      @viragomann
                      Yes.Correct.

                      V 1 Reply Last reply Reply Quote 0
                      • V
                        viragomann @Rostyslav Didus
                        last edited by

                        @rostyslav-didus
                        So consider that you have to populate the route for the access servers tunnel network on the s2s remote sites.

                        Rostyslav DidusR 1 Reply Last reply Reply Quote 0
                        • Rostyslav DidusR
                          Rostyslav Didus @viragomann
                          last edited by

                          @viragomann
                          Server side
                          Скриншот 07-06-2021 09.20.09.png
                          Vpn server settings for users with openvpn gui client.
                          As you see,I entered all subnets to ipv4 local networks.
                          Should I add here tunnel network subnets?
                          vpn tun for remote.png

                          Client side+server side for tunnel 1
                          1.png
                          Client side+server side for tunnel 2
                          2.png
                          Client side+server side for tunnel 3
                          3.png

                          When I connect via openvpn gui and trying tracert command to 10.10.104.2(windows server) I receive time out.
                          Скриншот 07-06-2021 09.40.57.png
                          If I try to connect to any subnet's server it works fine when I initialize connection from one of those subnet(10.10.100.0/23,10.10.98.0/23 etc.)
                          Скриншот 07-06-2021 09.49.10.png

                          V 1 Reply Last reply Reply Quote 0
                          • V
                            viragomann @Rostyslav Didus
                            last edited by

                            @rostyslav-didus
                            You have to add the access server tunnel network 10.1.5.0/24 to the "Remote networks" on all remote sites, so that the branch routers set a route for it pointing to the main.

                            Rostyslav DidusR 1 Reply Last reply Reply Quote 1
                            • Rostyslav DidusR
                              Rostyslav Didus @viragomann
                              last edited by

                              @viragomann,
                              My Lord!
                              It works now.Added 10.1.5.0/24 to each "remote networks" configuration.
                              I appreciate that.😊
                              Thanks a lot.
                              Скриншот 07-06-2021 12.07.06.png

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.