Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    client connect via openvpn, ping OK to complete Lan, but no access

    Scheduled Pinned Locked Moved OpenVPN
    4 Posts 3 Posters 342 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bforpcB
      bforpc
      last edited by

      Hi,
      i have created a pfsense client connection, described here with the assistant.
      So the client can connect to pfsense from the internet and can ping all the Servers in the intranet now ... but can not acccess them via ports 22/80/443 and others.
      There is an autocreated rule, what should enable access:
      Bildschirmfoto vom 2020-02-11 11-53-47.png
      Also there is an autogenerated wan rule:
      Bildschirmfoto vom 2020-02-11 11-55-16.png

      Second question:
      in the clinet settings, i had set the to export the client Network (so the intranet behind pfsense can access to the vpn client machine). But the client Ip ist not reachable or pingable.

      Bfo

      1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by

        Better follow the official netgate documentation/guides.
        For OpenVPN RAS check out
        https://www.youtube.com/watch?v=qscIIZ10WTQ
        https://www.youtube.com/watch?v=iJ5GACqfIGs
        https://docs.netgate.com/pfsense/en/latest/book/openvpn/using-the-openvpn-server-wizard-for-remote-access.html
        https://docs.netgate.com/pfsense/en/latest/book/openvpn/troubleshooting-openvpn.html

        -Rico

        1 Reply Last reply Reply Quote 1
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          And your sure these services are running? And there is no firewall on them that would block access to those services from your source network (the vpn tunnel network).

          To me the first step is validate the traffic is being sent or not.. If you sniff on the lan interface when you try and access from vpn client - do you see pfsense sending 22/80/443 onto the destination IP in the lan.. If so then problem is downstream of pfsense.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 1
          • bforpcB
            bforpc
            last edited by

            I try to sniff the packets to see whats going on.

            Bfo

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.