• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Localhost unable to ping over multiwan VPN

Scheduled Pinned Locked Moved Routing and Multi WAN
3 Posts 2 Posters 372 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    jstride
    last edited by Feb 23, 2021, 9:50 PM

    I have a couple of physical interfaces in a routing group, using this group the firewall can ping external addresses with no issues.

    As soon as I add a gateway group with an OpenVPN gateway as priority 1 I lose the ability to ping (Time to live exceeded)/update packages/etc. on the firewall. The same gateway is fine for selective routing from my internal VLAN interfaces.

    Do I need to add something in NAT for the firewall to be able to communicate? I am running Hybrid Outbound NAT otherwise the OpenVPN connections "don't work".

    V 1 Reply Last reply Feb 23, 2021, 10:33 PM Reply Quote 0
    • V
      viragomann @jstride
      last edited by Feb 23, 2021, 10:33 PM

      @jstride said in Localhost unable to ping over multiwan VPN:

      Do I need to add something in NAT for the firewall to be able to communicate?

      Yes, you have to add an outbound NAT rule for pfSense (127.0.0.0/8) to that VPN interface.

      J 1 Reply Last reply Feb 25, 2021, 10:48 AM Reply Quote 0
      • J
        jstride @viragomann
        last edited by Feb 25, 2021, 10:48 AM

        @viragomann adding that for outbound NAT, unfortunately, doesn't fix the problem, still can't ping/curl from the firewall.

        The VPN interfaces don't have any firewall rules (and work from the internal VLAN/interfaces) is there anything else I need to do.

        pftop gives a state of 0:0 for localhost to external IPs and time to live exceeded when using the VPN interface, but I don't even see pftop entries when using the default WAN gateway.

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received