Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVpn Routing

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 4 Posters 566 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dariovernelli
      last edited by

      Hi,
      please help me.
      I have this kind of configuration: Pfsense with LAN interface 172.31.1.81/16, Wan and OPT1 172.30.198.0/24 interface.
      I have to configure a vpn between pfsese OPT1 net and a remote Gl-Inet 4G router where internal lan is 192.168.8.0/24

      I configured a OpenVpn server in this way:
      Screenshot 2020-11-26 at 13.55.43.png

      Screenshot 2020-11-26 at 13.57.08.png
      Screenshot 2020-11-26 at 13.57.23.png

      Exported the configuration, the VPN is up and running,
      Screenshot 2020-11-26 at 14.03.39.png
      but from OPT1 I can't ping or traceroute the remote IPs 192.168.8.0/24, but I can do the reverse thing, from 192.168.8.0 I can ping 172.30.198.0.....
      It seems that the pfsense don't have a route to 192.168.8.0......So I put a static:
      Screenshot 2020-11-26 at 14.06.35.png
      but nothing has changed.....

      What is wrong ? Where are my issues ?

      Thanks a lot for your answers
      Dario

      JKnottJ 1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        Don't use public IP ranges for a VPN tunnel network! Also for a site-2-site a /30 mask will be sufficient.
        Don't use static routes with VPN gateways! The route is set by OpenVPN.

        Possibly the remote router blocks access from your OPT1.

        1 Reply Last reply Reply Quote 0
        • JKnottJ
          JKnott @dariovernelli
          last edited by

          @dariovernelli

          Why are you using 223.0.0.0 /25? You should be using something from RFC 1918. Also, you don't need a /25, unless you have several clients. If it's just a single client at the other end, a /30 can be used or even /31, though that may cause problems for Windows.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          A 1 Reply Last reply Reply Quote 0
          • A
            a527408965 @JKnott
            last edited by

            @JKnott said in OpenVpn Routing:

            /31

            /31? It's that work??

            JKnottJ 1 Reply Last reply Reply Quote 0
            • JKnottJ
              JKnott @a527408965
              last edited by

              @a527408965

              Yes, though, as I mentioned, it might cause problems with Windows. The original thought behind a /30 was you needed 2 addresses for the end points and 1 each for broadcast and network, but neither of the latter is needed for a point to point link.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              1 Reply Last reply Reply Quote 1
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.