Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Static route from/to LAN to/from OpenVPN

    Scheduled Pinned Locked Moved NAT
    2 Posts 2 Posters 796 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Y
      yyovchev
      last edited by

      Hello there.
      I have pfsense with openvpn connection to remote VPN server. (pfsense is a client and receive static route from vpn server 192.168.2.0/23).
      I have 1 LAN network (192.168.100.0/24).

      I have ping from pfsense to IPs over openvpn connection (for example 192.168.2.1, 192.168.2.88, 192.168.3.88 etc.)
      I wanna LAN network of pfsense (192.168.100.0/24) to have access to networks over OpenVPN (192.168.2.0/23).

      This is pfsense route tables:

      IPv4
      Destination Gateway Flags Use Mtu Netif Expire
      default MY_ISP_GW UGS 2950183 1500 bce1
      xx.xx.xx.xx/29 link#6 U 47024 1500 bce1
      xx.xx.xx.xx link#6 UHS 0 16384 lo0
      127.0.0.1 link#9 UH 16 16384 lo0
      192.168.2.0/23 192.168.3.5 UGS 55010 1500 ovpnc1
      192.168.3.0/24 192.168.3.5 UGS 36 1500 ovpnc1
      192.168.3.5 link#11 UH 0 1500 ovpnc1
      192.168.3.6 link#11 UHS 0 16384 lo0
      192.168.100.0/24 link#1 U 5379684 1500 bce0
      192.168.100.1 link#1 UHS 0 16384 lo0

      (xx.xx.xx.xx is our public IP addresses)

      Can you help me what static rules, or NAT settigs must be create to work connection from LAN network (192.168.100.0/24) to OpenVPN side (192.168.2.0/23)

      Best wishes,

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        Does your remote side know it needs to go down the vpn connection to get to 192.168.100.. Sounds like you setup a roadwarrior connection.  You more than likely want a site to site if your connecting to sites together.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.