Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Lan client computers do not ping

    Scheduled Pinned Locked Moved OpenVPN
    10 Posts 2 Posters 802 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jucelio_rosa
      last edited by

      Hello .

      I've set up a site-to-site VPN, but I can't ping computers on the client's lan network.

      On the server, I correctly configured the ip of the remote lan network. Rules were created releasing the icmp protocol
      on the lan interface, on the wan interface and on the openvpn interface of the client server.

      Does anyone know what the problem could be?

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @jucelio_rosa
        last edited by

        @jucelio_rosa common user error is forgetting host firewalls, which normally default to blocking stuff like a ping from some unknown network.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        J 1 Reply Last reply Reply Quote 0
        • J
          jucelio_rosa @johnpoz
          last edited by

          @johnpoz I thought about this hypothesis, however, I found it strange that no host ping

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @jucelio_rosa
            last edited by johnpoz

            @jucelio_rosa strange about what..

            I have some device on site A 192.168.1.42 that goes through a vpn to ping some box 192.168.2.24..

            Why would the host firewall running on 192.168.2.24 default to allow 192.168.1.42 to ping it?? Its not on the 192.168.2/24 network, etc..

            Windows firewall for sure defaults blocking icmp from non local networks..

            This for sure is like the number 1 reason for what you describe as your problem - just read the boards, this same exact question comes up like every other day.. I setup a vpn and can not ping box over the vpn..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            J 2 Replies Last reply Reply Quote 0
            • J
              jucelio_rosa @johnpoz
              last edited by

              @johnpoz I understood.
              At the moment I'm at the company's headquarters (where I have the firewall server) and my boss is at the branch company, where we have the firewall client.
              I already asked him to check the windows firewalls on the client computers.

              johnpozJ 1 Reply Last reply Reply Quote 0
              • J
                jucelio_rosa @johnpoz
                last edited by

                @johnpoz When we noticed the problem, I looked at the settings and realized that on the server I had misconfigured the ip of the remote network.
                I fixed it, restarted the service, but the problem persists.
                Do you think restarting the firewall client can solve this?

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @jucelio_rosa
                  last edited by

                  @jucelio_rosa said in Lan client computers do not ping:

                  I already asked him to check the windows firewalls on the client computers.

                  Most of the time users of computers have no clue how to do that - even if they are the boss ;)

                  This takes 2 seconds to troubleshoot.. Why don't you just sniff on your pfsense for your sites - do you see the traffic going across them?.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  J 1 Reply Last reply Reply Quote 0
                  • J
                    jucelio_rosa @johnpoz
                    last edited by

                    @johnpoz said in Lan client computers do not ping:

                    Most of the time users of computers have no clue how to do that - even if they are the boss ;)
                    This takes 2 seconds to troubleshoot.. Why don't you just sniff on your pfsense for your sites - do you see the traffic going across them?.

                    My friend, you are right.
                    Disabling windows firewall ping worked. Thank you very much.
                    Do you know what rule I need to create in the Windows firewall so that I can leave it active and at the same time the ping works correctly?

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @jucelio_rosa
                      last edited by

                      @jucelio_rosa ping while nice to test connectivity - you prob need to allow for whatever it is you actually want to do to this machine across the vpn.

                      I personally don't see why user in site A should need to talk to user machine in site B, I could see a file server or something... But why should users in A talk to users in B machines directly? Just seems like way for ransomware to spread if you ask me..

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      J 1 Reply Last reply Reply Quote 0
                      • J
                        jucelio_rosa @johnpoz
                        last edited by

                        @johnpoz It would be because of a software configuration.

                        Thank you very much for your attention. Now everything is ok.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.