Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN Mobile IPSec unable to access LAN machines

    Scheduled Pinned Locked Moved IPsec
    5 Posts 2 Posters 621 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • U
      user1089082098
      last edited by user1089082098

      Hello everyone,

      I am stuck with a problem for a few days.
      I have 3 OVH instances in a private network (vrack) (10.0.1.0/24). One of the instance is a pfSense firewall (10.0.1.254).

      I did setup a VPN mobile IPSec tunnel (192.168.1.0/24), and I can connect successfully using Windows default client. While i'am connected, i can ping and ssh into the pfSense without any problem.
      I'am trying to access the other OVH instances through this tunnel but I can't figure out :(

      Firewall rule :
      7336d7a4-cee7-4633-bfed-ee01f7eed126-image.png
      Traffic is being allowed by this rule :
      0867f40d-927c-45fe-a4bd-c94edd657c05-image.png
      But the machine does not receive the packet :
      47567600-dd41-4ce0-aca1-0afc24733ec0-image.png

      I tried to create routes but i'am not sure of what am i doing :
      c83a73db-2458-49f5-b829-98a7b7be2995-image.png

      (Every instance can ping each other)

      Any help would be very appreciated :)

      perikoP 1 Reply Last reply Reply Quote 0
      • perikoP
        periko @user1089082098
        last edited by

        @user1089082098 Can u show your phase 2 settings?

        What mobile setup ? EAP-TLS, EAPMSCHAPv..?

        Is a split tunnel or full tunnel?

        Pfsense version?

        Regards!!!

        Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
        www.bajaopensolutions.com
        https://www.facebook.com/BajaOpenSolutions
        Quieres aprender PfSense, visita mi canal de youtube:
        https://www.youtube.com/c/PedroMorenoBOS

        U 2 Replies Last reply Reply Quote 0
        • U
          user1089082098 @periko
          last edited by

          @periko Here are my phase 2 settings :
          994da9fb-5373-4cd5-86ad-7049d728e4db-1.png
          6250f419-e53a-4a34-9bab-799207ae4b36-2.png

          I'am using EAP-TLS to authenticate my users.

          I just upgraded to 2.7.2.

          It is a full tunnel.

          Thanks for your reply :)

          perikoP 1 Reply Last reply Reply Quote 0
          • U
            user1089082098 @periko
            last edited by user1089082098

            @periko I did a NAT rule :
            Interface Source Source port Destination Destination port NAT Address NAT port Static port
            LAN * * 10.0.1.0/24 * LAN Address * crossed arrow

            and now my vpn client can communicate with my LAN instances. This was probably due to the OVH firewall that is dropping the packets because of the src address not falling within the subnet.

            But I still don't know how to give access to internet from those instances.

            Actually the default NAT rules is :
            127.0.0.0/8 ::1/128 10.0.1.0/24 192.168.1.0/24 * * * WAN address *

            But i think using the WAN Address to NAT the internet traffic will produce the same error, since the address is not falling within the subnet

            1 Reply Last reply Reply Quote 0
            • perikoP
              periko @user1089082098
              last edited by

              @user1089082098 If u can, send me a message and we see if we can help u.

              Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
              www.bajaopensolutions.com
              https://www.facebook.com/BajaOpenSolutions
              Quieres aprender PfSense, visita mi canal de youtube:
              https://www.youtube.com/c/PedroMorenoBOS

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.