Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN or NAT?

    Scheduled Pinned Locked Moved NAT
    5 Posts 2 Posters 322 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      thewho
      last edited by stephenw10

      I've spent ~12 days trying to figure this all out. I've been told it could be NAT and by others OpenVPN so i don't know where to post.

      I've created two LAB networks and placed them on VLAN23 (Called "Home", Switch Port 23) and VLAN24 (Called "Office", Switch Port 24).

      I have gotten MOST things working but i cannot get the AP/NAS ("Home") or AP/NAS ("Office") to be able to connect to each other.

      db7048d5-3f0c-4c1c-a2a5-9b1e4714a256-image.png

      Firewall rules for now are simple. "* * ALLOW ALL" on all interfaces and their WAN interfaces "Block private networks and loopback addresses", "Block bogon networks" are unchecked.

      replacement-image.png

      "Home" is the OpenVPN Server Peer-to-Peer between them.
      On "Home" routing looks like this:
      5fe4c237-0f3b-4c58-9009-54af2328c1d8-image.png 91e7b0e9-aac0-4872-90aa-c19faaf7026d-image.png

      And on "Office" routing looks like this:
      ccaa1b0b-1b63-4ebb-8c31-9af28db50772-image.png

      TL;DR:
      I cannot get AP/NAS (192.168.30.0/25, VLAN30) or AP/NAS (192.168.30.128/25, VLAN30) to reach each other over OpenVPN tunnel (horizontal dotted line on the Diagram). But both SG-1100 can reach both of the NAS/AP. Everything else does seem to work fine.

      NAT is set to "Auto".

      I'm really at the end of the road.. Before starting this all i did not even have basic knowledge of VLAN so lot's of stuff here is still a bit new to me but i have used m0n0wall/pfSense for many years. So if anyone could point me in the right direction that would mean the world to me.

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @thewho
        last edited by

        @thewho
        Did you configure a client specific override and if so, is it applied properly?

        T 2 Replies Last reply Reply Quote 1
        • T
          thewho @viragomann
          last edited by

          @viragomann I had to look. No. I do not have one for that tunnel but i had one for each of the other two.. I set it up as two different tunnels and i haven't really understood what "Client Specific override" is good for but i know i had two add it for the other two..

          1 Reply Last reply Reply Quote 0
          • T
            thewho @viragomann
            last edited by

            @viragomann YOU SOLVED IT!!!!!!!!!!!!!!!!!!!!!!!!! YOU FREAKING SOLVED IT!!!!!! I'm so happy i'm almost about to cry!! It's finally working!!!

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @thewho
              last edited by

              @thewho
              Glad that you it working.

              1 Reply Last reply Reply Quote 1
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.