Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN to internal network NAT

    Scheduled Pinned Locked Moved NAT
    nat
    3 Posts 2 Posters 864 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Sytec
      last edited by

      Hello all,
      I have a strange behavior after updating to the release 2.5.2.

      The OpenVpn clients cannot connect to the SY-ASTERISK PBX because they are refused by the PBX security rules. Investigating the problem I found that the OpenVpn clients reach the PBX with the IP of the internal lan of the firewall (10.100.80.254) instead of the OpenVpn IP (192.168.190.X).
      How I can deeply investigate this problem?

      Thank you.

      This is a simplified network diagram
      eed32db0-68c7-441e-a9a8-2e128581e579-image.png

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @Sytec
        last edited by

        @sytec said in OpenVPN to internal network NAT:

        I found that the OpenVpn clients reach the PBX with the IP of the internal lan of the firewall (10.100.80.254) instead of the OpenVpn IP (192.168.190.X).

        That is done by Firewall > NAT > Outbound NAT. There might be a rule for the LAN interface.

        If it's in automatic mode pfSense only adds a rule, when you set a gateway on the LAN, which should not be done as long as there are no special reasons.

        S 1 Reply Last reply Reply Quote 0
        • S
          Sytec @viragomann
          last edited by

          @viragomann

          Thank you for your reply.

          The lan interface gateway is empty and the NAT is set in 'Manual Outbound NAT rule generation'.
          In any case I found the problem, there was a NAT rule configured to a network interface group with the LAN interface included.

          Avevo controllato many time NAT configuration! 🤦

          Thank you very much!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.