• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Having problems connecting two OpenVPN-Servers

Scheduled Pinned Locked Moved OpenVPN
4 Posts 2 Posters 678 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • H
    Hope-IT-Works
    last edited by Hope-IT-Works Apr 23, 2023, 11:33 PM Apr 23, 2023, 11:31 PM

    Hello and thank you for reading.

    We have the problem, that our office is only connected via mobile communications, but a VPN tunnel is required so that the devices in the office can be accessed remotely.

    Since the office is only connected via mobile communications, there is no way to open a port.

    Accordingly, this VPN tunnel must be tunneled via a separate server in the cloud. For this, I installed pfSense in the cloud with a static IP address.

    I created 2 OpenVPN servers:

    1. Server to Client

    • This is the VPN server that users will connect to

    2. Site to Site

    • The pfSense instance in the office connects to this VPN server.

    Both VPN tunnels work by themselves. But accessing a device in the office remotely is not yet possible. I adopted the configuration as described here: https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-bridged.html

    Unfortunately, access to the devices in the office still does not work.

    Here is a diagram of the current setup (Image):
    70764e07-f3d1-4371-af40-50ccdcd31d9a-VPN.png

    I'm grateful to everyone trying to help resolve this issue.

    If more information is needed, don't hesitate to request it.

    Thank you and greetings from Germany.
    Tobias
    @Hope-IT-Works

    V 1 Reply Last reply Apr 24, 2023, 2:03 PM Reply Quote 0
    • V
      viragomann @Hope-IT-Works
      last edited by Apr 24, 2023, 2:03 PM

      @hope-it-works said in Having problems connecting two OpenVPN-Servers:

      I adopted the configuration as described here: https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-bridged.html

      We don't like this mode here in the forum. It results into many troubles and you don't need tap mode to achieve what you intend to.

      I recommend to set up a normal remote access server for clients access: https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-ra.html#openvpn-remote-access-configuration-example
      And a site-to-site for connecting your office: https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-s2s-tls.html#openvpn-site-to-site-configuration-example-with-ssl-tls

      If you've configured all properly access from clients should work flawlessly after.
      If you have troubles with it come back, you will get help here.

      H 1 Reply Last reply Apr 24, 2023, 11:41 PM Reply Quote 0
      • H
        Hope-IT-Works @viragomann
        last edited by Apr 24, 2023, 11:41 PM

        @viragomann Thanks for your reply. That's what I had configured before. There I couldn't use the same subnet for both VPN servers.

        I should mention that we currently don't have a LAN Interface. Is a LAN interface required for this setup?

        If yes, could I configure a VLAN with the WAN as the parent interface for this purpose?

        Thank you.

        V 1 Reply Last reply Apr 25, 2023, 9:53 AM Reply Quote 0
        • V
          viragomann @Hope-IT-Works
          last edited by Apr 25, 2023, 9:53 AM

          @hope-it-works said in Having problems connecting two OpenVPN-Servers:

          That's what I had configured before. There I couldn't use the same subnet for both VPN servers.

          That's correct. But is there any reason for needing both to be within the same layer 2?
          For accessing services that's not a requirement at all.

          I should mention that we currently don't have a LAN Interface. Is a LAN interface required for this setup?

          You only need access to the pfSense GUI to configure it. If you have open the WAN for this purpose, you don't need a LAN interface.

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received