<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[LAN through Open VPN not accesible]]></title><description><![CDATA[<p dir="auto">Accesing server LAN side not possible through OpenVPN.<br />
this is the scheme:<br />
<img src="https://ibb.co/4PXJFxj" alt="Network Scheme" class=" img-fluid img-markdown" /><br />
<a href="https://ibb.co/4PXJFxj" target="_blank" rel="noopener noreferrer nofollow ugc">link scheme image</a><br />
I have been checking posts but no results yet!.<br />
Any suggestions?<br />
Thank you so much!</p>
]]></description><link>https://forum.netgate.com/topic/152732/lan-through-open-vpn-not-accesible</link><generator>RSS for Node</generator><lastBuildDate>Sat, 11 Jul 2026 23:39:14 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/152732.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 20 Apr 2020 13:34:16 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to LAN through Open VPN not accesible on Thu, 23 Apr 2020 13:32:30 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jimp">@<bdi>jimp</bdi></a></p>
<p dir="auto">Hi again!<br />
I have been checking some points like LAN router NAT, and server configs and through the packet capture on pfsense I've found this capturing OpenPVN packets:<br />
15:01:08.596584 IP 192.168.168.2.51978 &gt; 192.168.168.10.3389: tcp 0<br />
15:01:08.596607 IP 192.168.168.2.51978 &gt; 192.168.168.10.3389: tcp 0<br />
15:01:08.596617 IP 192.168.168.1 &gt; 192.168.168.2: ICMP redirect 192.168.168.10 to host 192.168.168.2, length 72</p>
<p dir="auto">where 192.168.168.2 its a wan connection over Open VPN(my phone) and 192.168.168.10 is the remote machine with RDP (WS2019), 192.168.168.1 is the LAN router. Look at the TCP 0??? What means?</p>
<p dir="auto">With firewall always disabled to test connections and no AV's and after 2 days testing several things, I've found 3 different scenarios:</p>
<ol>
<li>RDP from LAN to LAN works on any computer. (W10Pro and WS 2019)</li>
<li>RDP from WAN to LAN works in a W10Pro but not in a WS2019 Datacenter only with Remote access (NO RDS) and same ip or network than W10Pro directly by default port 3389. Tested with a PC the error reported is: "internal Error" and tested with my phone the error is: 0x4 or 0x104<br />
3.RDP from WAN to LAN over OpenVPn doesn't work  in any computer at default port 3389, same errors.</li>
</ol>
<p dir="auto">Note the different OS behavior!!.</p>
<p dir="auto">CONFIGS:<br />
OPEN VPN<br />
WAN  UDP4 / 1194  192.168.168.0/27<br />
Crypto: AES-256-GCM/SHA512<br />
D-H Params: 4096 bits  OPEN VPN (tun3)<br />
IPv4 Tunnel Network 192.168.168.0/27</p>
<p dir="auto">OUTBOUND NAT MODE:<br />
  WAN  127.0.0.0/8 ::1/128 172.16.16.0/24 192.168.168.0/27  *  *  500  WAN address  *    Auto created rule for ISAKMP<br />
  WAN  127.0.0.0/8 ::1/128 172.16.16.0/24 192.168.168.0/27  *  *  *  WAN address  *    Auto created rule</p>
<p dir="auto">PORT FORWARD:<br />
WAN  TCP  *  *  WAN address  3389 (MS RDP)  172.16.16.1  3389 (MS RDP)  RDP</p>
<p dir="auto">OPEN VPN RULES:<br />
IPv4 *  *  *  *  *  *  none     OpenVPN OPEN VPN wizard</p>
<p dir="auto">WAN RULES:<br />
IPv4 UDP  *  *  10.10.10.11  1194 (OpenVPN)  *  none     OPEN VPN</p>
<p dir="auto">Any idea? Do you need some specific info?<br />
Thank you very much!!</p>
]]></description><link>https://forum.netgate.com/post/907423</link><guid isPermaLink="true">https://forum.netgate.com/post/907423</guid><dc:creator><![CDATA[ReneMG]]></dc:creator><pubDate>Thu, 23 Apr 2020 13:32:30 GMT</pubDate></item><item><title><![CDATA[Reply to LAN through Open VPN not accesible on Mon, 20 Apr 2020 20:04:12 GMT]]></title><description><![CDATA[<p dir="auto">Thanks, I'm going to check some of your suggestions. I'm sure I'll be back with more doubts...</p>
]]></description><link>https://forum.netgate.com/post/906704</link><guid isPermaLink="true">https://forum.netgate.com/post/906704</guid><dc:creator><![CDATA[ReneMG]]></dc:creator><pubDate>Mon, 20 Apr 2020 20:04:12 GMT</pubDate></item><item><title><![CDATA[Reply to LAN through Open VPN not accesible on Mon, 20 Apr 2020 15:39:57 GMT]]></title><description><![CDATA[<p dir="auto">It should work fine so long as every node along the path has proper routes. The OpenVPN client needs to have routes all the way through to the target system. The target system needs to know how to get traffic back to OpenVPN. Same with firewall rules, you need to pass through the traffic.</p>
<p dir="auto">But without more specific information about the OpenVPN setup, routes, and so on, it's impossible to say where your problem may be.</p>
<p dir="auto">There are some general suggestions on https://docs.netgate.com/pfsense/en/latest/routing/connectivity-troubleshooting.html for troubleshooting this kind of thing, like checking route tables, using traceroute and packet captures to diagnose, etc.</p>
]]></description><link>https://forum.netgate.com/post/906623</link><guid isPermaLink="true">https://forum.netgate.com/post/906623</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Mon, 20 Apr 2020 15:39:57 GMT</pubDate></item></channel></rss>