Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Subnets for Wireguard and OpenVPN

    Scheduled Pinned Locked Moved WireGuard
    3 Posts 2 Posters 192 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      demux
      last edited by

      Hi!
      Wireguard and OpenVPN servers need a subnet. To fully and transparently access the LAN subnet, shall I give them sub-subnets of the LAN or is it ok to give them a completely different subnet? (Is access some sort of translated/NATed?) Some services like samba are restricted to LAN clients and SSH asks for 2FA if coming from elsewhere, some services may only be accessed from LAN subnet.
      Thanks!
      -demux

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @demux
        last edited by

        @demux said in Subnets for Wireguard and OpenVPN:

        Wireguard and OpenVPN servers need a subnet. To fully and transparently access the LAN subnet, shall I give them sub-subnets of the LAN

        This would be a bad idea. You cannot use the same subnet twice or overlapping partially.

        or is it ok to give them a completely different subnet?

        Yes. Use any unused private network range, as small as necessary.

        (Is access some sort of translated/NATed?)

        No, but you can configure NAT if desired.

        Some services like samba are restricted to LAN clients and SSH asks for 2FA if coming from elsewhere, some services may only be accessed from LAN subnet.

        So configure the services security settings accordingly so that they accept connections from outside, or even do nat, which just circumvents security restrictions.

        1 Reply Last reply Reply Quote 1
        • D
          demux
          last edited by

          So, in the past we did everything right.
          Thank you.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.