• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

WEBGUI access from VPN

Scheduled Pinned Locked Moved OpenVPN
8 Posts 2 Posters 974 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • H
    hajdeo
    last edited by Jul 24, 2023, 4:08 PM

    Hi guys,

    I have successfully launched the VPN client, the connection is active and working.

    9ae29ea1-75ed-4605-825b-dc196e3ecf4f-image.png
    95d22d5d-d0b0-4914-904e-82480cc3cc83-image.png

    Suppose the external VPN address is XXX.XXX.XXX.XXX.XXX and I would need to access the router or WebGui through this address.I already managed to get it to work once, but I had to reset the settings and I can't do it again.

    Do I need to configure somehow the interface, port forward?

    Here si pics of config :
    0a2d821e-71ca-4461-acfc-495cce254bea-image.png

    a8d033ae-92a5-488d-8f37-787745710f86-image.png

    af0a3666-c271-4cea-bc4b-b858f575ab7d-image.png

    thank you!!!

    V 1 Reply Last reply Jul 24, 2023, 4:23 PM Reply Quote 0
    • V
      viragomann @hajdeo
      last edited by Jul 24, 2023, 4:23 PM

      @hajdeo
      Generally you should not allow webGUI access on WAN. But this is, what your Anti-Lockout rule does.
      Note that this setting allows webGUI access without VPN.

      Also your manually added WAN rule allows any TCP traffic to the WAN interface.

      Add a rule to the OpenVPN interface allow access. Then access it by using the OpenVPN server IP.
      Or assign a virtual private IP to WAN (Firewall > virtual IPs) of type "IP alias" and add this in the OpenVPN server settings to the "Local Networks". Then you can use this to access the webGUI. Consider to add a proper rule on the OpenVPN tab.

      H 1 Reply Last reply Jul 24, 2023, 4:48 PM Reply Quote 0
      • H
        hajdeo @viragomann
        last edited by Jul 24, 2023, 4:48 PM

        @viragomann Hi, thanks for your time.

        9b89b4f4-fc73-496f-a29a-43acb174b9bb-image.png

        added but nothing happend....any sugestion?

        V 1 Reply Last reply Jul 24, 2023, 5:00 PM Reply Quote 0
        • V
          viragomann @hajdeo
          last edited by Jul 24, 2023, 5:00 PM

          @hajdeo
          You cannot access the WAN address through the VPN. So this rule is pretty useless.
          The WAN address cannot be routed through the VPN, otherwise the VPN wouldn't stay alive.

          I recommended to access the webGUI either by the OpenVPN servers virtual IP or by a manually virtual, which you've to assign to the WAN interface before.
          The OpenVPN servers IP is the first usable IP out of the tunnel network.
          You can also assign an additional virtual IP to the VPN interface, however, you would have to assign an interface to the OpenVPN instance and enable it at before.

          H 1 Reply Last reply Jul 24, 2023, 8:01 PM Reply Quote 0
          • H
            hajdeo @viragomann
            last edited by Jul 24, 2023, 8:01 PM

            @viragomann

            hm...can you please provide me step-by-step how add virtual IP?.....if you have a time?

            tahnk you so much!

            V 1 Reply Last reply Jul 24, 2023, 9:29 PM Reply Quote 0
            • V
              viragomann @hajdeo
              last edited by Jul 24, 2023, 9:29 PM

              @hajdeo
              I just noticed, that you're running an OpenVPN client. I was thinking about a server.
              What is the goal of this setup, running a vpn client on a router, which only has a single WAN.
              And obviously this WAN interface has a private IP. So pfSense might be behind another router.

              So you I'm wondering from where you want to access it. From the server network?
              You should be able to access it simply by the clients virtual IP.

              Do you have a CSO on the server for this client? This would be needed to access any other IP that the clients virtual IP from the server side.

              H 1 Reply Last reply Jul 24, 2023, 9:47 PM Reply Quote 0
              • H
                hajdeo @viragomann
                last edited by Jul 24, 2023, 9:47 PM

                @viragomann I want to access it from the internet. I don't have a public public IP, this way I can access pfsense webgui directly using the client. I already had it set up this way once, but I had to reset the router and I can't get it set up

                H 1 Reply Last reply Jul 25, 2023, 1:04 AM Reply Quote 0
                • H
                  hajdeo @hajdeo
                  last edited by Jul 25, 2023, 1:04 AM

                  @hajdeo said in WEBGUI access from VPN:

                  @viragomann I want to access it from the internet. I don't have a public public IP, this way I can access pfsense webgui directly using the client. I already had it set up this way once, but I had to reset the router and I can't get it set up

                  hi frien...is done :) my opsense webgui is accessable from internet, just added this to port forwarding :)
                  e7e5fa37-cc9c-4533-b4b3-ca40006f3bc5-image.png

                  Do you think, is possible add rule to access another LAN IP adress (where is plex) from internt through this VPN connection?

                  1 Reply Last reply Reply Quote 0
                  8 out of 8
                  • First post
                    8/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received