Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVpn Nat problem

    OpenVPN
    2
    4
    2.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Y
      yena
      last edited by

      Hi,
      I've been banging my head against the wall on this issue for a couple of days and need some help. I am running 1.2 STABLE
      and i have setup OpenVPN.
      I would like to connect from internet to the protected server in the LAN :

      INTERNET –---> (wan 83.103.59.189 ) Pfsense ( lan 192.168.1.1) -----> ( 192.168.1.2) Server web,ftp,telnet..

      I successfully Open and connect from a Windows Client to the Pfsense VPN server but i can't connect to the Server..
      it seem a Nat problem.
      When i open the VPN i use the VPN IP to connect to the server: telnet 192.168.3.1

      My OpenVPN Pfsense settings:
      Protocol: UDP
      Dynamic IP: Yes
      Local port: 1194
      Address pool: 192.168.3.0/24
      Use static IPs: No
      Local network:
      Remote network:
      Client-to-client VPN:
      Cryptography: BF-CBC (128-bit)
      Authentication method: PKI
      LZO compression: yes

      Nat settings:
      Automatic outbound NAT rule generation (IPsec passthrough)

      I attach the Firewall Rules and other settings

      lan-fw.gif
      lan-fw.gif_thumb
      OpenVPN.gif
      OpenVPN.gif_thumb
      outbond.gif
      outbond.gif_thumb
      port-forward.gif
      port-forward.gif_thumb
      wan-fw.gif
      wan-fw.gif_thumb
      win-vpn.gif
      win-vpn.gif_thumb

      1 Reply Last reply Reply Quote 0
      • K
        kpa
        last edited by

        The address pool (192.168.3.0/24 in your case) is just for the point-to-point addresses of the tunnel interface, you can't reach anything on your LAN using those addresses, you have to use the LAN network addresses to connect to any host on your LAN.

        1 Reply Last reply Reply Quote 0
        • Y
          yena
          last edited by

          THANKSSS !! Yes this is my error  :o

          1 Reply Last reply Reply Quote 0
          • Y
            yena
            last edited by

            Can i do the same with PPTP ?
            Or PPTP enable connection only from the same natwork of WAN ?
            Because i try it and i can connect to 192.168.1.2 only from WAN class..

            Thanks !

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.