Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    New OpenVPN server, can connect but can't get to LAN subnet.

    Scheduled Pinned Locked Moved OpenVPN
    51 Posts 4 Posters 7.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      fatman032 @viragomann
      last edited by

      @viragomann Sorry had a bad night just wanting to get this working.
      Here is the routing table for the pi.
      5bc89aed-5a33-48c1-9ea0-570809f376d9-image.png

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @fatman032
        last edited by

        @fatman032
        And what's the LAN IP of pfSense? Does it match?

        F 1 Reply Last reply Reply Quote 0
        • F
          fatman032 @viragomann
          last edited by fatman032

          @viragomann Yes they Match. The LAN is 192.168.192.0/24
          Here you go. It has new IP since it no longer has a reservation.
          e96d6a88-4b40-4e0d-bbb7-eb020cccfb54-image.png

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @fatman032
            last edited by

            @fatman032 said in New OpenVPN server, can connect but can't get to LAN subnet.:

            Yes they Match. The LAN is 192.168.192.0/24

            That's not a proper Interface IP, that's a network address.

            F 1 Reply Last reply Reply Quote 0
            • F
              fatman032 @viragomann
              last edited by fatman032

              @viragomann Here you go.
              89b16473-49b6-4822-823c-8ab012d16e89-image.png

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @fatman032
                last edited by

                @fatman032
                All right. So I cannot tell you, why you run into these out-of-state blocks on LAN:
                eb3bd731-2534-4e37-8184-a131372e174a-grafik.png

                Since the source port is 80 and the flag is SA, these are definitely respond packets SYN packets. And presumably pfSense did never see the respective SYN packets.

                Okay, do you connect your VPN clients from inside your LAN?

                F 1 Reply Last reply Reply Quote 0
                • F
                  fatman032 @viragomann
                  last edited by

                  @viragomann no I have been using my cell as a hotspot.

                  V 1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @fatman032
                    last edited by

                    @fatman032 said in New OpenVPN server, can connect but can't get to LAN subnet.:

                    no I have been using my cell as a hotspot.

                    Also cut all internal connections?

                    Need to see the clients routing table to get closer.

                    F 1 Reply Last reply Reply Quote 0
                    • F
                      fatman032 @viragomann
                      last edited by

                      @viragomann

                      Also cut all internal connections?

                      Yes, I turn off the Wi-Fi.

                      Need to see the clients routing table to get closer.

                      0ed490ff-215b-409e-8088-ed2500fe518c-image.png

                      V 1 Reply Last reply Reply Quote 0
                      • V
                        viragomann @fatman032
                        last edited by viragomann

                        @fatman032
                        Looks well.

                        Ensure that also your cell phone has no internal connection at the time you test the VPN via the hotspot.

                        I'm sure, there must be something wrong in your setup. You have obviously an asymmetric routing issue on the VPN.
                        For further investigation I can only suggest to sniff the traffic on all involved interface while you try to access the LAN from the VPN client.
                        I guess, the SYN packets don't come in on the VPN interface.

                        F 1 Reply Last reply Reply Quote 0
                        • F
                          fatman032 @viragomann
                          last edited by

                          Well after hours of trying different things. I think I might have found the fix. I have no idea if this was the fix because of the number of things I was trying at the end but this makes since to me. I didn't have these boxes checked and when pfSense made the gateways it didn't check the boxes automatically.

                          24bde76f-16f2-4739-9ca8-a7ec475914ae-image.png

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.