Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Dual WAN failover mode, traffic issue with OpenVPN, I can reach LAN gateway but not the ip on LAN, why?

    Scheduled Pinned Locked Moved Routing and Multi WAN
    8 Posts 2 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      Elrick75
      last edited by

      Hello everybody,

      I'm having an issue where as soon as I turn on a gateway group, i follow tuto here and video here

      When i try to connect with OpenVPN, VPN server and the client both say the VPN is connected but it's just not passing traffic.
      I am able to ping the default gateway on the target lan, but not able to ping every device on it.

      Before this, though, the VPN is working fine.

      I have created a group gateway and i've allowed everything in the firewall rules for every LAN interface by adding my group gateway as gateway.

      3c726d70-e91b-45ee-8380-4d058cbec0d8-image.png

      2edbab5c-3f3a-49d5-8949-d30f7a60e228-image.png

      f6876152-9c3a-47b8-b626-1d15289192ec-image.png

      Does i miss something?
      Many thanks for your help.

      V 1 Reply Last reply Reply Quote 0
      • E
        Elrick75
        last edited by

        to complete:

        33bb4feb-eb1c-4d39-a597-e04fdf6750d1-image.png

        06f22ccf-7475-4a25-b5a8-19678827d52c-image.png

        19cbc772-061e-4451-98d7-22d8d9c755e0-image.png

        2dd54395-40a1-4bf4-a30f-c348ac1cf8cd-image.png

        1 Reply Last reply Reply Quote 0
        • V
          viragomann @Elrick75
          last edited by

          @elrick75 said in Dual WAN failover mode, traffic issue with OpenVPN, I can reach LAN gateway but not the ip on LAN, why?:

          i've allowed everything in the firewall rules for every LAN interface by adding my group gateway as gateway.

          That was a bad decision at all.
          So you turned all firewall rules into policy routing rule directing all traffic to the active gateway.

          Changing the default gateway to the gateway group is all you had to do.

          So edit your rule again and remove the gateway setting.

          E 1 Reply Last reply Reply Quote 0
          • E
            Elrick75 @viragomann
            last edited by

            @viragomann said in Dual WAN failover mode, traffic issue with OpenVPN, I can reach LAN gateway but not the ip on LAN, why?:

            Changing the default gateway to the gateway group is all you had to do.
            So edit your rule again and remove the gateway setting.

            Just to be sure to understand.
            You suggest to me switch Gateway from Groupe_Gateway to Default on every rules right ?

            be661e71-bc56-453e-a61e-7d248255c625-image.png

            c7b9f3b2-2eb9-4511-bcb7-4c40114e6c5d-image.png

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @Elrick75
              last edited by

              @elrick75
              No. That is the default gateway setting. It is correct.

              But the firewall rules should not have a gateway set.
              d9afeed5-34d8-4221-9987-97deba281811-grafik.png

              E 1 Reply Last reply Reply Quote 0
              • E
                Elrick75 @viragomann
                last edited by Elrick75

                @viragomann

                Hi
                I change it, now it is like this (Gateway = * on every rules) :

                9a95d9af-5fa4-4ae9-81d4-2d52233fb2f0-image.png

                But remote VPN connexion is not able to reach device on LAN (VLAN_DMZ), just able to ping the default gateway on this subnet.

                d726428a-6764-4dc9-b12d-de46c4e881d9-image.png

                My NAT rules details:

                2fb420f7-aee2-4059-8ca4-9042ce8bab3d-image.png

                I disable rules on WAN interface used before when i used only one WAN connection, that might have explained something, but the problem still remains ;(

                e09ec61c-6024-419b-90c5-883a65930193-image.png

                @jimp @johnpoz @jwt If you can please help me, many thanks in advance.

                E 1 Reply Last reply Reply Quote 0
                • E
                  Elrick75
                  last edited by Elrick75

                  This post is deleted!
                  1 Reply Last reply Reply Quote 0
                  • E
                    Elrick75 @Elrick75
                    last edited by Elrick75

                    I find why....
                    I had set Group Gateway as defaut gateway on OpenVPN rules too, i switch it to default (= * ) and all is working fine now.

                    f148e2dd-73bf-4092-9bc5-e73db3ccf6b4-image.png

                    I have another specific question.

                    Before switching to Dual Wan, I was able to connect from my home in VPN to my home :)
                    That is to say from the VLAN MY LAN I connect with VPN to the VLAN_DMZ, which was convenient for security reasons and to manage VLAN_DMZ.
                    Even if I was still depending on my ISP to access VLAN_DMZ, I didn't have to have a machine on the VLAN_DMZ at home.

                    Since I am in DUAL Wan, I am not able to do this anymore.
                    When trying to connect from my MY LAN VLAN, i receive TLS Error, OpenVPN client log :

                    Sun May 15 10:54:05 2022 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
                    Sun May 15 10:54:05 2022 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
                    Sun May 15 10:54:05 2022 MANAGEMENT: >STATE:1652604845,RESOLVE,,,,,,
                    Sun May 15 10:54:05 2022 TCP/UDP: Preserving recently used remote address: [AF_INET]185.XXX.XXX.XXX:53XXX
                    Sun May 15 10:54:05 2022 Socket Buffers: R=[65536->65536] S=[64512->64512]
                    Sun May 15 10:54:05 2022 UDPv4 link local: (not bound)
                    Sun May 15 10:54:05 2022 UDPv4 link remote: [AF_INET]185.XXX.XXX.XXX:53XXX
                    Sun May 15 10:54:05 2022 MANAGEMENT: >STATE:1652604845,WAIT,,,,,,
                    Sun May 15 10:55:05 2022 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
                    Sun May 15 10:55:05 2022 TLS Error: TLS handshake failed]
                    Sun May 15 10:55:05 2022 SIGUSR1[soft,tls-error] received, process restarting
                    Sun May 15 10:55:05 2022 MANAGEMENT: >STATE:1652604905,RECONNECTING,tls-error,,,,,
                    

                    Is there a specific parameter in the OpenVPN configuration file that could solve this?
                    Do you know if it is possible to solve this problem?

                    Thank you.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.