Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense Openvpn server and client connected but not working

    Scheduled Pinned Locked Moved OpenVPN
    21 Posts 3 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kiruba
      last edited by

      Dear All,

      i have one small problem, need someone advise. i am configured open vpn server at one end it have only wan interface and in other side i am installed pfsense client has wan and lan interface both side are configured. Open vpn status showing connected but i am not able ping or remote desktop i cannot able to access. please help me to resolve the problem.
      Note: firewall rule also added stil problem was there.
      Something i need to do with server pfsense nat setting. i dont knw to fix it.

      regards

      Kiruba
      ![Open server client A.JPG](/public/imported_attachments/1/Open server client A.JPG)
      ![Open server client A.JPG_thumb](/public/imported_attachments/1/Open server client A.JPG_thumb)
      ![Status Connected.JPG](/public/imported_attachments/1/Status Connected.JPG)
      ![Status Connected.JPG_thumb](/public/imported_attachments/1/Status Connected.JPG_thumb)
      ![Client B.JPG](/public/imported_attachments/1/Client B.JPG)
      ![Client B.JPG_thumb](/public/imported_attachments/1/Client B.JPG_thumb)
      ![Client B VPN Status.JPG](/public/imported_attachments/1/Client B VPN Status.JPG)
      ![Client B VPN Status.JPG_thumb](/public/imported_attachments/1/Client B VPN Status.JPG_thumb)

      1 Reply Last reply Reply Quote 0
      • K
        kiruba
        last edited by

        any advise please

        1 Reply Last reply Reply Quote 0
        • V
          viragomann
          last edited by

          It's hard to follow, what you've exactly set up.

          Do have one server and two clients or only one client or two servers with multiple clients??
          Open server client A.JPG shown a client connected to port 1194, obviously to a remote access server.
          Status Connected.JPG shows a site-to-site server listening on port 1195.
          :o

          Please tell what you've exactly configured in OpenVPN and post your settings.

          1 Reply Last reply Reply Quote 0
          • K
            kiruba
            last edited by

            Thank you so much for your reply.

            my requirement explained in my network topoloqy.

            ![Untitled Diagram.jpg](/public/imported_attachments/1/Untitled Diagram.jpg)
            ![Untitled Diagram.jpg_thumb](/public/imported_attachments/1/Untitled Diagram.jpg_thumb)

            1 Reply Last reply Reply Quote 0
            • K
              kiruba
              last edited by

              Please see my configure file. Please help me.

              Thanks

              Kiruba

              ![Server Conf1.JPG](/public/imported_attachments/1/Server Conf1.JPG)
              ![Server Conf1.JPG_thumb](/public/imported_attachments/1/Server Conf1.JPG_thumb)
              ![Server Conf2.JPG](/public/imported_attachments/1/Server Conf2.JPG)
              ![Server Conf2.JPG_thumb](/public/imported_attachments/1/Server Conf2.JPG_thumb)
              ![client conf1.JPG](/public/imported_attachments/1/client conf1.JPG)
              ![client conf1.JPG_thumb](/public/imported_attachments/1/client conf1.JPG_thumb)
              ![client conf2.JPG](/public/imported_attachments/1/client conf2.JPG)
              ![client conf2.JPG_thumb](/public/imported_attachments/1/client conf2.JPG_thumb)

              1 Reply Last reply Reply Quote 0
              • V
                viragomann
                last edited by

                So the site A pfSense has only WAN interface and you try to access other devices on the WAN network?

                Please tell if you're running multiple vpn instances (client or server) on one site. That's essential.

                1 Reply Last reply Reply Quote 0
                • K
                  kiruba
                  last edited by

                  yes..

                  In both location one server and client instance running. you're right  One file name screen shot: 192.168.9.254 and in another 192.168.2.250. my previous diagram i am mentioned.

                  Thanks

                  kiruba

                  screenshot.jpg
                  screenshot.jpg_thumb
                  192.168.2.250.JPG
                  192.168.2.250.JPG_thumb

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    What is the IP address you are trying to connect from?

                    What is the IP address you are trying to connect to?

                    Please try not to use terms like "I cannot ping desktop servers" Nobody knows what that is.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • K
                      kiruba
                      last edited by

                      sorry for my bad english. i want to connect from 87.233.50.200(site B Client) to 82.236.52.82(Site A server)

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        No. The real, inside IP addresses of the hosts you are pinging from and to. Not the WAN addresses. Once the tunnel is up those don't matter any more.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • K
                          kiruba
                          last edited by

                          Dear,

                          Server A side

                          Lan interface not configured:
                          Only WAN Address: 192.168.2.250
                          Static IP Address : 82.236.52.82
                          Vpn tunnel: 10.18.18.0 /24
                          Clint B side:

                          PFsene or LAN Interface IP: 192.168.9.254
                          WAN Address: 82.233.50.200
                          Static IP Address: 82.533.50.200.

                          i am ping from 192.168.2.*** to 192.168.9.** not able to do

                          1 Reply Last reply Reply Quote 0
                          • DerelictD
                            Derelict LAYER 8 Netgate
                            last edited by

                            I am asking for a specific IP address on each side and you still give ***.

                            What is the default gateway set on host 192.168.2.*** ???

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            1 Reply Last reply Reply Quote 0
                            • K
                              kiruba
                              last edited by

                              Default gateway on 192.168.2.250 is 192.168.1.10
                              Deafult gateway set on 192.168.9. 254  is 87.**.2*.201.

                              1 Reply Last reply Reply Quote 0
                              • DerelictD
                                Derelict LAYER 8 Netgate
                                last edited by

                                No. The default gateways set on the two end hosts that are trying to communicate over the VPN.

                                Please provide their exact IP addresses and their set default gateways.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • K
                                  kiruba
                                  last edited by

                                  Dear Derelict,

                                  i am not understand can you explain me deeply. please help me

                                  Regards

                                  kiruba

                                  1 Reply Last reply Reply Quote 0
                                  • K
                                    kiruba
                                    last edited by

                                    viragomann and Derelict any suggestion please

                                    1 Reply Last reply Reply Quote 0
                                    • DerelictD
                                      Derelict LAYER 8 Netgate
                                      last edited by

                                      i am ping from 192.168.2.*** to 192.168.9.** not able to do

                                      What, exact host is 192.168.2.***?

                                      What, exactly, is the default gateway configured on that host?

                                      What, exact host is 192.168.9.**?

                                      What, exactly, is the default gateway configured on that host?

                                      Chattanooga, Tennessee, USA
                                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                      1 Reply Last reply Reply Quote 0
                                      • K
                                        kiruba
                                        last edited by

                                        @Derelict:

                                        i am ping from 192.168.2.*** to 192.168.9.** not able to do

                                        What, exact host is 192.168.2.***?

                                        What, exactly, is the default gateway configured on that host?

                                        What, exact host is 192.168.9.**?

                                        What, exactly, is the default gateway configured on that host?

                                        Screen shot was attached…

                                        ![GW Server A.JPG](/public/imported_attachments/1/GW Server A.JPG)
                                        ![GW Server A.JPG_thumb](/public/imported_attachments/1/GW Server A.JPG_thumb)
                                        ![Client GW.JPG](/public/imported_attachments/1/Client GW.JPG)
                                        ![Client GW.JPG_thumb](/public/imported_attachments/1/Client GW.JPG_thumb)
                                        ![client lan gw.JPG](/public/imported_attachments/1/client lan gw.JPG)
                                        ![client lan gw.JPG_thumb](/public/imported_attachments/1/client lan gw.JPG_thumb)

                                        1 Reply Last reply Reply Quote 0
                                        • DerelictD
                                          Derelict LAYER 8 Netgate
                                          last edited by

                                          No. The hosts you are pinging to/from on those networks.

                                          Chattanooga, Tennessee, USA
                                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                          1 Reply Last reply Reply Quote 0
                                          • K
                                            kiruba
                                            last edited by

                                            @Derelict:

                                            No. The hosts you are pinging to/from on those networks.

                                            No i am not able to ping… only status showing connected...

                                            But in the Diagonists states it was showing multiple:mulitple.

                                            Regards

                                            kiruba

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.