<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Full Tunnel OpenVPN need remote LAN access]]></title><description><![CDATA[<p dir="auto">I ran into a problem here hopefully there's a way to work around it.</p>
<p dir="auto">I have two offices with two Netgate routers. There is an IPSec tunnel between the routers, so Office 2 can access Office 1 LAN resources.<br />
Office 1 LAN: 10.0.2.0/24<br />
Office 2 LAN: 10.0.3.0/24</p>
<p dir="auto">Office 2  is outside the US and some websites they use are blocked for outside the US. So I created OpenVPN server with client export with option "Force all client-generated IPv4 traffic through the tunnel" which is basically a full tunnel. It works fine and routes all client traffic tru Office 1, but I lost access to the Office 1 LAN subnet 10.0.2.0/24 where they are accessing a certain app.</p>
<p dir="auto">Users are connecting vie the OpenVPN connect app.<br />
How can I preserve the OpenVPN full tunnel connection and have access to the Office 1 LAN subnet?</p>
<p dir="auto">Thanks.</p>
]]></description><link>https://forum.netgate.com/topic/188308/full-tunnel-openvpn-need-remote-lan-access</link><generator>RSS for Node</generator><lastBuildDate>Wed, 22 Jul 2026 11:18:13 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/188308.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 20 May 2024 19:10:18 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Full Tunnel OpenVPN need remote LAN access on Tue, 21 May 2024 18:35:46 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bitvoip">@<bdi>bitvoip</bdi></a></p>
<p dir="auto">well great! Always good to discover and fix problems.</p>
]]></description><link>https://forum.netgate.com/post/1170373</link><guid isPermaLink="true">https://forum.netgate.com/post/1170373</guid><dc:creator><![CDATA[The Party of Hell No]]></dc:creator><pubDate>Tue, 21 May 2024 18:35:46 GMT</pubDate></item><item><title><![CDATA[Reply to Full Tunnel OpenVPN need remote LAN access on Tue, 21 May 2024 18:00:39 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/the-party-of-hell-no">@<bdi>The-Party-of-Hell-No</bdi></a> I have those rules in place. I found what my problem was after adding the route options in the advanced box. I have two WANs and I had to select the second WAN to be as default Gateway so they can come out with the correct IP and access to LAN works now.</p>
<p dir="auto">Thanks for your help.</p>
]]></description><link>https://forum.netgate.com/post/1170367</link><guid isPermaLink="true">https://forum.netgate.com/post/1170367</guid><dc:creator><![CDATA[bitvoip]]></dc:creator><pubDate>Tue, 21 May 2024 18:00:39 GMT</pubDate></item><item><title><![CDATA[Reply to Full Tunnel OpenVPN need remote LAN access on Tue, 21 May 2024 17:38:09 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bitvoip">@<bdi>bitvoip</bdi></a><br />
There are two rules to be added. The first is a WAN Rule for OpenVPN to route out the WAN - it should be added automatically by the wizard</p>
<p dir="auto">The second is the "Pass to any rule." At this point to get it to work leave wide open - in the future you can insert restrictions.<br />
In: Firewall &gt; Rules &gt; OpenVPN (Or whatever you called your OpenVPN server) add rules which allow OpenVPN route to any.</p>
<p dir="auto">Where I found information:<br />
https://blog.miniserver.it/en/pfsense/pfsense-and-openvpn-guide-to-creating-and-configuring-a-road-warrior-vpn-server/</p>
]]></description><link>https://forum.netgate.com/post/1170363</link><guid isPermaLink="true">https://forum.netgate.com/post/1170363</guid><dc:creator><![CDATA[The Party of Hell No]]></dc:creator><pubDate>Tue, 21 May 2024 17:38:09 GMT</pubDate></item><item><title><![CDATA[Reply to Full Tunnel OpenVPN need remote LAN access on Tue, 21 May 2024 17:00:47 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/the-party-of-hell-no">@<bdi>The-Party-of-Hell-No</bdi></a> It did not work. I can ping the remote router, but no other device on that LAN.</p>
]]></description><link>https://forum.netgate.com/post/1170360</link><guid isPermaLink="true">https://forum.netgate.com/post/1170360</guid><dc:creator><![CDATA[bitvoip]]></dc:creator><pubDate>Tue, 21 May 2024 17:00:47 GMT</pubDate></item><item><title><![CDATA[Reply to Full Tunnel OpenVPN need remote LAN access on Mon, 20 May 2024 20:42:15 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/the-party-of-hell-no">@<bdi>The-Party-of-Hell-No</bdi></a> Thank you! I will give it a try.</p>
]]></description><link>https://forum.netgate.com/post/1170221</link><guid isPermaLink="true">https://forum.netgate.com/post/1170221</guid><dc:creator><![CDATA[bitvoip]]></dc:creator><pubDate>Mon, 20 May 2024 20:42:15 GMT</pubDate></item><item><title><![CDATA[Reply to Full Tunnel OpenVPN need remote LAN access on Mon, 20 May 2024 20:27:20 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bitvoip">@<bdi>bitvoip</bdi></a></p>
<p dir="auto">In the Openvpn server custom options under advanced configuration add a push:</p>
<p dir="auto">#Command to force Openvpn onto LAN;<br />
push "route 172.31.54.0 255.255.255.0";</p>
<p dir="auto">Where 172.31.54.0 is your network IP</p>
]]></description><link>https://forum.netgate.com/post/1170217</link><guid isPermaLink="true">https://forum.netgate.com/post/1170217</guid><dc:creator><![CDATA[The Party of Hell No]]></dc:creator><pubDate>Mon, 20 May 2024 20:27:20 GMT</pubDate></item></channel></rss>