Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Successful ping when VPN client is deactivated

    Scheduled Pinned Locked Moved OpenVPN
    4 Posts 2 Posters 522 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Mufflon
      last edited by

      Hi ,
      I'm still new in this topic and maybe I just don't get it :/

      I successfully created a VPN client and all traffic is routed through the tunnel.
      whenever I deactivate the client all devices in the LAN do not have any access to the internet… using the terminal and the "ping" command is unsuccessful... no magic, absolutely clear.

      However, using the ping function from Diagnostics --> Ping leads to successful response from the respective server even if the client is deactivated.
      This is somehow strange since I would suggest that also traffic from the pfsense machine itself is routed through the tunnel... :o
      Furthermore, the check for update function at the dashboard also works when the VPN client is deactivated.

      So... could someone please tell me whether I configured something wrong?!

      Cheers

      1 Reply Last reply Reply Quote 0
      • M
        Mufflon
        last edited by

        No ideas?  :(

        1 Reply Last reply Reply Quote 0
        • jahonixJ
          jahonix
          last edited by

          At least you're thinking somewhat wrong.

          Your pfSense creates a connection to the outside, usually your ISP. If you setup a VPN on top of that to reach some destination it's still something on top of the basic internet connection.
          Think of pfSense as a shoe box with interfaces poking out. With rules you can control what comes into that shoe box. You cannot control what goes out.
          This also means that your pfSense can always ping out any interface (or check for updated). It is the shoe box.

          1 Reply Last reply Reply Quote 0
          • M
            Mufflon
            last edited by

            Oh, thx for that plausible example. That makes sense ;)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.