<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[NAT Hairpinning for OpenVPN Server]]></title><description><![CDATA[<p dir="auto">I'm running a OpenVPN Server on the pfsense router.  I can connect to it just fine from the Internet, but not from inside my network.  I understand that NAT Hairpinning is probably the problem.  Has anybody got this working?  Any instructions on how to achieve it?</p>
]]></description><link>https://forum.netgate.com/topic/136499/nat-hairpinning-for-openvpn-server</link><generator>RSS for Node</generator><lastBuildDate>Wed, 13 May 2026 15:47:27 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/136499.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 08 Oct 2018 19:00:03 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to NAT Hairpinning for OpenVPN Server on Tue, 09 Oct 2018 16:20:51 GMT]]></title><description><![CDATA[<p dir="auto">That should of been addressed by your client and your AP as well.  For example unifi release firmware back in oct 2017 to address 3.9.3 anything above should be fine.</p>
<p dir="auto">But sure being able to leave the vpn on makes it simple.</p>
]]></description><link>https://forum.netgate.com/post/796037</link><guid isPermaLink="true">https://forum.netgate.com/post/796037</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Tue, 09 Oct 2018 16:20:51 GMT</pubDate></item><item><title><![CDATA[Reply to NAT Hairpinning for OpenVPN Server on Tue, 09 Oct 2018 15:52:13 GMT]]></title><description><![CDATA[<p dir="auto">I went through my firewall rules, and everything looked good.  Dug into the VPN logs, and I can see the client trying to connect.  I figured it was erroring out from routing issues with NAT Hairpinning.  Figured out that it's trying to use IPv6.  I disabled all IPv6 related options, and now it connects fine.</p>
<p dir="auto">Now the VPN connects from my phone, regardless of what network I'm connected to.  Doesn't matter if it's LTE or WiFi, it seemlessly transitions between both.  So now I don't have to constantly toggle the VPN on and off whenever I leave my house.</p>
<p dir="auto">Any vulnerabilities in WPA2 are now mitigated via the VPN:</p>
<p dir="auto">https://arstechnica.com/information-technology/2017/10/severe-flaw-in-wpa2-protocol-leaves-wi-fi-traffic-open-to-eavesdropping/</p>
]]></description><link>https://forum.netgate.com/post/796023</link><guid isPermaLink="true">https://forum.netgate.com/post/796023</guid><dc:creator><![CDATA[bedub1]]></dc:creator><pubDate>Tue, 09 Oct 2018 15:52:13 GMT</pubDate></item><item><title><![CDATA[Reply to NAT Hairpinning for OpenVPN Server on Mon, 08 Oct 2018 20:26:54 GMT]]></title><description><![CDATA[<p dir="auto">You having a problem resolving the dynamic dns your pointing to your public IP?  What are the firewall rules on interface wifi is connected to?</p>
<p dir="auto">My question is more to what is the point of doing this in the first place - is your own local wifi a hostile network?  Who else is on this wifi network?</p>
]]></description><link>https://forum.netgate.com/post/795847</link><guid isPermaLink="true">https://forum.netgate.com/post/795847</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 08 Oct 2018 20:26:54 GMT</pubDate></item><item><title><![CDATA[Reply to NAT Hairpinning for OpenVPN Server on Mon, 08 Oct 2018 20:21:32 GMT]]></title><description><![CDATA[<p dir="auto">Look at the created states. Probably filtering on the OpenVPN port is a good place to start.</p>
]]></description><link>https://forum.netgate.com/post/795846</link><guid isPermaLink="true">https://forum.netgate.com/post/795846</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Mon, 08 Oct 2018 20:21:32 GMT</pubDate></item><item><title><![CDATA[Reply to NAT Hairpinning for OpenVPN Server on Mon, 08 Oct 2018 20:17:09 GMT]]></title><description><![CDATA[<p dir="auto">If you don't think it's a hairpinning issue, I'll check my firewall rules again.</p>
<p dir="auto">Is there any way to watch the packet hit pfsense, and see where it's trying to route it?</p>
]]></description><link>https://forum.netgate.com/post/795842</link><guid isPermaLink="true">https://forum.netgate.com/post/795842</guid><dc:creator><![CDATA[bedub1]]></dc:creator><pubDate>Mon, 08 Oct 2018 20:17:09 GMT</pubDate></item><item><title><![CDATA[Reply to NAT Hairpinning for OpenVPN Server on Mon, 08 Oct 2018 20:13:48 GMT]]></title><description><![CDATA[<p dir="auto">You can for sure connect to your public IP from your lan side - that is not a hairpin your just coming from the lan side..  Are you forwarding traffic that hits your public IP on your vpn port to loopback or something?</p>
<p dir="auto">Are you saying its not connecting?  What are you rules on the interface your wifi connection?</p>
]]></description><link>https://forum.netgate.com/post/795841</link><guid isPermaLink="true">https://forum.netgate.com/post/795841</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 08 Oct 2018 20:13:48 GMT</pubDate></item><item><title><![CDATA[Reply to NAT Hairpinning for OpenVPN Server on Mon, 08 Oct 2018 20:08:55 GMT]]></title><description><![CDATA[<p dir="auto">VPN endpoint DNS entry is a public DNS name, pointing to the WAN IP of the router.</p>
<p dir="auto">My traffic flow is:</p>
<p dir="auto">WiFi VLAN -&gt; WAN IP -&gt; OpenVPN on PFSense</p>
<p dir="auto">Near as I can tell all my firewall rules should allow this.  I figure it's being blocked by NAT Hairpinning, as it's a common issue when you have a flow like this:</p>
<p dir="auto">WiFi VLAN -&gt; WAN IP -&gt; LAN IP VPN Server</p>
]]></description><link>https://forum.netgate.com/post/795838</link><guid isPermaLink="true">https://forum.netgate.com/post/795838</guid><dc:creator><![CDATA[bedub1]]></dc:creator><pubDate>Mon, 08 Oct 2018 20:08:55 GMT</pubDate></item><item><title><![CDATA[Reply to NAT Hairpinning for OpenVPN Server on Mon, 08 Oct 2018 19:46:37 GMT]]></title><description><![CDATA[<p dir="auto">Sounds like he wants to connect and talk to the internet, but be protected while on his inside unsecured wifi.</p>
<p dir="auto">Seems that should "just work" but I have never tried it. If the same hostname is used to connect to as is the name of the firewall there are probably hosts file entries pointing that name to an inside address. That won't work.</p>
]]></description><link>https://forum.netgate.com/post/795832</link><guid isPermaLink="true">https://forum.netgate.com/post/795832</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Mon, 08 Oct 2018 19:46:37 GMT</pubDate></item><item><title><![CDATA[Reply to NAT Hairpinning for OpenVPN Server on Mon, 08 Oct 2018 19:27:25 GMT]]></title><description><![CDATA[<p dir="auto">So on your on your local wifi network - and you want to vpn to your pfsense public IP vpn server, to talk to your local network??  Huh??</p>
]]></description><link>https://forum.netgate.com/post/795829</link><guid isPermaLink="true">https://forum.netgate.com/post/795829</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 08 Oct 2018 19:27:25 GMT</pubDate></item><item><title><![CDATA[Reply to NAT Hairpinning for OpenVPN Server on Mon, 08 Oct 2018 19:26:56 GMT]]></title><description><![CDATA[<p dir="auto">OK. Where does NAT come into play? Are you port forwarding your OpenVPN connections into WAN to somewhere else?</p>
]]></description><link>https://forum.netgate.com/post/795828</link><guid isPermaLink="true">https://forum.netgate.com/post/795828</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Mon, 08 Oct 2018 19:26:56 GMT</pubDate></item><item><title><![CDATA[Reply to NAT Hairpinning for OpenVPN Server on Mon, 08 Oct 2018 19:06:39 GMT]]></title><description><![CDATA[<p dir="auto">The OpenVPN network and the network of the VPN client are different networks.</p>
<p dir="auto">I have my phone set to require to send all traffic over VPN.  But on WiFi the connection fails to connect and thus no data is transferred.  This also allows you to connect to an Open WiFi network, with VPN for encryption.</p>
]]></description><link>https://forum.netgate.com/post/795821</link><guid isPermaLink="true">https://forum.netgate.com/post/795821</guid><dc:creator><![CDATA[bedub1]]></dc:creator><pubDate>Mon, 08 Oct 2018 19:06:39 GMT</pubDate></item><item><title><![CDATA[Reply to NAT Hairpinning for OpenVPN Server on Mon, 08 Oct 2018 19:03:47 GMT]]></title><description><![CDATA[<p dir="auto">Why would you want to do that?</p>
<p dir="auto">If you connect from the same network that is the Local network in OpenVPN that won't work.</p>
]]></description><link>https://forum.netgate.com/post/795818</link><guid isPermaLink="true">https://forum.netgate.com/post/795818</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Mon, 08 Oct 2018 19:03:47 GMT</pubDate></item></channel></rss>