Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Openvpn works only with first lan

    OpenVPN
    2
    5
    2.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mgiammarco
      last edited by

      Hello,

      I have a setup with pfsense running as an openvpn client to an external server.

      It works very well:pfsense servers on lan can see remote servers.

      Now I have added to pfsense several vlan (opt1, opt2, etc.) but the pc on these subnets cannot see remote servers: their gateway (pfsense) route the data to internet and not to openvpn.

      It seems that only pfsense lan gateway has the right routing table.

      What can I do?

      Thanks in advance for any help.

      Mario

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        How do your firewall rules on the OPTx interfaces look like?
        Did you create routes for the additional subnets on the remote site? (with the route command in the custom options).

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • M
          mgiammarco
          last edited by

          @GruensFroeschli:

          How do your firewall rules on the OPTx interfaces look like?
          Did you create routes for the additional subnets on the remote site? (with the route command in the custom options).

          Yes I have tried with routes and also with static routes. But the problem is that firewall rules on lan are the same of opt1: lan works, opt1 not works.

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            The problem isnt with the firewall rules on the local side.
            The problem lies with the routes on the remote site.

            What is on the remote side?
            You need to add routes on the remote site! Not on the local pfSense.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • M
              mgiammarco
              last edited by

              Sigh, you are right, my fault: a wrong subnet mask did not allow new routes.

              Thank you!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.