Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Mobile Ipsec cannot connect from guest wifi when behind same pfsense box

    Scheduled Pinned Locked Moved IPsec
    6 Posts 3 Posters 707 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Y
      yasnick
      last edited by yasnick

      Hello, I cannot figure out how to make our Guest clients to be able to connect to the mobile vpn when behind the same pfSense box.

      Using version 2.4.3-RELEASE-p1 (amd64)

      1 Reply Last reply Reply Quote 0
      • A
        avinash1003
        last edited by

        Do you find any blocked entry in Firewall logs ?

        1 Reply Last reply Reply Quote 0
        • NogBadTheBadN
          NogBadTheBad
          last edited by

          Post your guest network firewall rules.

          I bet its a block rule on your guest interface.

          Not exactly sure why you'd want guest users vpning into the same pfSense router.

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          Y 1 Reply Last reply Reply Quote 0
          • Y
            yasnick @NogBadTheBad
            last edited by

            @nogbadthebad

            We have a policy to prevent users from using company resources over wifi.

            But some users with vpn access want to connect over vpn.

            I have a block rule on the guest interface for sure to prevent users from accessing the lan and the firewall itself, but they are allowed to go to the internet via a gateway.

            My question is why can't we connect to the vpn if traffic goes out of the gateway correctly.

            NogBadTheBadN 1 Reply Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad @yasnick
              last edited by NogBadTheBad

              @yasnick said in Mobile Ipsec cannot connect from guest wifi when behind same pfsense box:

              @nogbadthebad

              We have a policy to prevent users from using company resources over wifi.

              Well they are using company resources over wi-fi if you let them vpn back in over wi-fi, if your allowing vpn over wi-fi you might as well create a separate SSID for company access and lock it down with radius access.

              Post your guest firewall rules as per my 1st post "I bet its a block rule on your guest interface"

              What IP address do they connect to for VPN, I bet its an address that encompasses This Firewall.

              This Firewall (self) - Any IP address assigned to any interface on this firewall (pfSense 2.2+)

              https://www.netgate.com/docs/pfsense/firewall/firewall-rule-basics.html

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              1 Reply Last reply Reply Quote 0
              • Y
                yasnick
                last edited by

                @NogBadTheBad

                Thank you for your message. I agree with your idea implementing Radius server, it makes sense in some way.

                The IP that they connect to the VPN is a virtual IP assigned to an interface. I better understand now.

                But on another pfsense box (version 2.3.4) we don't have this issue and we can connect to the vpn from a lan interface.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.