Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    VPN client access is blocked while connected to VPN server

    Scheduled Pinned Locked Moved Firewalling
    10 Posts 3 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      tstorm
      last edited by

      I have a freenas machine with a transmission jail that connects to airvpn. At home I have no problem accessing it and has full Internet connectivity. However, when I connect to my pfsense openvpn server I can access everything on my lan but not my transmission jail. I thought I might be PFBlockerNG but have disabled and it still won't work. Still pretty new to PFsense and firewalling in general.

      1 Reply Last reply Reply Quote 0
      • T Offline
        tstorm
        last edited by

        Anyone? If you have questions about the setup I can go into more detail…

        1 Reply Last reply Reply Quote 0
        • V Offline
          viragomann
          last edited by

          Maybe the jail blocks access from unknown subnets like your VPN IP. If that's the issue you can solve it by doing outbound NAT at pfSense.

          1 Reply Last reply Reply Quote 0
          • T Offline
            tstorm
            last edited by

            I thought that may be part of the answer. I had someone else on reddit run me through trying to setup static routes and it didn't work. So I'll look into outbound NAT. Any tips?

            1 Reply Last reply Reply Quote 0
            • V Offline
              viragomann
              last edited by

              Add a rule:
              interface: LAN (or which one your NAS is connected to)
              source: VPN tunnel subnet
              dest: NAS jail
              translation: interface address

              Your outound NAT has to be set to hybrid or manual rule generation.

              1 Reply Last reply Reply Quote 0
              • KOMK Offline
                KOM
                last edited by

                https://doc.pfsense.org/index.php/Outbound_NAT

                1 Reply Last reply Reply Quote 0
                • T Offline
                  tstorm
                  last edited by

                  @viragomann:

                  Add a rule:
                  interface: LAN (or which one your NAS is connected to)
                  source: VPN tunnel subnet
                  dest: NAS jail
                  translation: interface address

                  Your outound NAT has to be set to hybrid or manual rule generation.

                  That didn't seem to do it. I tried adding in the IP to the jail in the destination field, but it kept changing the IP to .0 instead of .2 at the end. Tried a few variations too, still no luck.

                  1 Reply Last reply Reply Quote 0
                  • V Offline
                    viragomann
                    last edited by

                    @tstorm:

                    but it kept changing the IP to .0 instead of .2 at the end.

                    Have you set the mask to /32?

                    You may also try any here.

                    1 Reply Last reply Reply Quote 0
                    • T Offline
                      tstorm
                      last edited by

                      Good call I'll try that soon.

                      1 Reply Last reply Reply Quote 0
                      • T Offline
                        tstorm
                        last edited by

                        Nope, didn't work. I already have a outbound rule that has my VPN subnet set to any dest. I can access everything else on my network, just not this jail and only when connected to vpn.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.