Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN to DMZ

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 2 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sisterpfsense
      last edited by

      Greetings!

      Project pretty close to completion.

      The final hurdle: VPN to DMZ connectivity.

      While connected to the network remotely via VPN (without TLS -not sure if this is relevant or not) I can't seem to ping or connect to any of the server in the DMZ. IS there a Rule or other options to Set.
      Thank you

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        Off course you need a firewall rule on VPN interface to allow the access. If you used the wizard for set up this rule should be allready there.

        Otherwise ensure that the pfSense running the VPN server is the default gateway in the DMZ.

        Also check if local SW-firewall on the server is blocking the access.

        1 Reply Last reply Reply Quote 1
        • S
          sisterpfsense
          last edited by

          Hi,

          Thanks for your assistance.

          I can confirm the DMZ auto rule exists.
          I can also conform their is no local firewall preventing ping (from the remote location I can ping servers in the 192.168.1.0 segment but nothing in the 192.168.50.0 segment).

          I am at a loss what to enter in the upstream gateway (pictured). 192.168.1.1 in the private side of the firewall and is blocked by deny LAnnet rule. Pfsense complains if i enter the official verizon fios upstream gateway. Not sure what should be entered.

          Any additional help appreciated.

          help_dmz_pfsense.jpg
          help_dmz_pfsense.jpg_thumb

          1 Reply Last reply Reply Quote 0
          • V
            viragomann
            last edited by

            The upstream gateway has only to be entered for WAN interfaces.

            Have you entered the DMZ subnet in the "Local network(s)" box in the VPN server settings to push the route to the client?
            To ensure check the clients routing table.

            1 Reply Last reply Reply Quote 1
            • S
              sisterpfsense
              last edited by

              Hero Member you are! Thank you very much!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.