Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN Breaks Vlan to Lan

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    10 Posts 3 Posters 712 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      KevCar2021
      last edited by

      Have 1 Vlan (30) that is bound to the Lan Interface. Both can talk to each other and go out to the internet. Once I enable VPN back to the Office they can no longer talk to each other. They both can talk to the Main Office network and Internet. Here are the Firewall rules for the Lan and the Vlan (EmployeeWireless)
      2b1f7498-b148-4bd8-a799-6e32d114a659-image.png
      dc1b6246-dc1d-42f6-a94f-c2003a0d2329-image.png

      Seems to be a routing issue. The system logs show a ping being allowed through the rule but does not work.

      NogBadTheBadN johnpozJ 2 Replies Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad @KevCar2021
        last edited by NogBadTheBad

        @kevcar2021 Why would it be a routing issue, both VLANS are directly attached.

        What are you using as an AP ?

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @KevCar2021
          last edited by

          @kevcar2021 said in VPN Breaks Vlan to Lan:

          Once I enable VPN back to the Office they can no longer talk to each other.

          Where are enabling vpn? On the client directly or via pfsense and policy routing out some gateway?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • K
            KevCar2021
            last edited by

            Under VPN->IPSec. I disable it.

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @KevCar2021
              last edited by

              @kevcar2021

              That shouldn't break anything - what are the remote networks involved and your local networks? Did you setup routed ipsec and doing policy routing?

              https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/routed-vti.html

              Your going to have to give some pieces of the puzzle if you want help solving it ;)

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • K
                KevCar2021
                last edited by

                Here is the Phase 2 of one of the networks. Currently I have 3. They are all configured the same.
                Just tell me what you wan to see I will show it. Thanks for the quick responses.
                I believe that is not Policy Routing correct?

                2bd0a56a-0f96-4d21-8317-d13fc69a16bf-image.png

                1 Reply Last reply Reply Quote 0
                • K
                  KevCar2021
                  last edited by

                  I am using Watchguard and Sonicwall Firewalls and have never had an issue like this. I am sure its something I am just missing. I want all Network activity to go through the VPN to the main office and then out their ISP. I am trying to replace an old Sonicwall and when I swap this one out with the Sonicwall everything works except for Vlan->Lan and vise versa. I have not tried the others as of yet.

                  1 Reply Last reply Reply Quote 0
                  • K
                    KevCar2021
                    last edited by

                    Here is the log of a ping from vlan 30 to the lan
                    Although it shows it went through the ping returns as Timed Out
                    e2def5c7-f674-48d2-b126-7098cda49d64-image.png

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @KevCar2021
                      last edited by

                      @kevcar2021 said in VPN Breaks Vlan to Lan:

                      ping from vlan 30 to the lan

                      And what interface did it go out? That just shows it was allow - you don't really know what other interface it left on - did it go out the vpn.. Which would explain why the dest never got it?

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      1 Reply Last reply Reply Quote 0
                      • K
                        KevCar2021
                        last edited by KevCar2021

                        What is the best way to determine that?
                        Here is something new. I am also unable to ping the VLAN interface when the vpn is connected. I started a continuous ping from the vlan to the vlan interface and to the device on the Lan. Both were returning time outs. I disabled the VPN and both pings started working. Once I re-enabled the VPN the pings started timing out again. Why would the ping return a timeout to its own interface?

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.