<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenVPN - Network Segment - Firewall Rule]]></title><description><![CDATA[<p dir="auto">I watched several postings on how to setup basic OpenVPN client access.</p>
<p dir="auto">I installed client export. Made reference to correct WAN DDNS target.. All seems good.  Client connect and they show DNS from LAN,  Route tables denoting the dedicated network within the environment, as well as routing to the Production LAN.  But the clients are NOT able to communicate.</p>
<p dir="auto">I do see resolution of MAC to router "VPN" interface, so L2 is definatly working, and route tables / DNS is correct.  My guess then is firewall rule.   But, in various videos, I did not see any examples where the VPN LAN segment needs to be set to allow ingress to the various Intranet VLANs.  Examples below</p>
<p dir="auto">Production LAN: VLAN 100   172.16.100.0/24  GW (router) .1<br />
DNS:  172.16.100.22<br />
VPN VLAN / Network:  172.16.104.0/24  GW (router) .1</p>
<p dir="auto">VPN:  IP leased to client 172.16.104.2/24<br />
Route:<br />
172.16.104.0/24  172.16.104.2<br />
172.16.100.0/24  172.16.104.1</p>
<p dir="auto">So all that looks normal.</p>
<p dir="auto">Firewall rule:  Only one for VPN  for ingress on WAN 1194,  destination any.</p>
<p dir="auto">So that look kocher.</p>
<p dir="auto">I don't think I have to create route logic within PFSense to forward.. but .. maybe I missed that part of the walk throughs.</p>
]]></description><link>https://forum.netgate.com/topic/172507/openvpn-network-segment-firewall-rule</link><generator>RSS for Node</generator><lastBuildDate>Sun, 19 Jul 2026 03:40:38 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/172507.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 29 May 2022 02:19:54 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to OpenVPN - Network Segment - Firewall Rule on Sun, 29 May 2022 13:47:21 GMT]]></title><description><![CDATA[<p dir="auto">You need a firewall rule to pass traffic from VPN clients coming in over the tunnel. That either has to be on the OpenVPN tab on the firewall rules page or the assigned interface tave if you have assigned the OpenVPN server as an interface. Be aware that the OpenVPN tab acts as an interface group that includes all OpenVPN servers and clients. If you have assigned an OpenVPN interface you usually want the rules on the assigned interface tab and <em>not</em> on the group openvpn tab.</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/1044345</link><guid isPermaLink="true">https://forum.netgate.com/post/1044345</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Sun, 29 May 2022 13:47:21 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN - Network Segment - Firewall Rule on Sun, 29 May 2022 02:41:33 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/penguinpages">@<bdi>penguinpages</bdi></a> said in <a href="/post/1044311">OpenVPN - Network Segment - Firewall Rule</a>:</p>
<blockquote>
<p dir="auto">examples where the VPN LAN segment needs to be set to allow ingress</p>
</blockquote>
<p dir="auto">Take a look at: https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/firewall-rules.html#allowing-traffic-over-openvpn-tunnels</p>
]]></description><link>https://forum.netgate.com/post/1044312</link><guid isPermaLink="true">https://forum.netgate.com/post/1044312</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Sun, 29 May 2022 02:41:33 GMT</pubDate></item></channel></rss>