Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NORDVPN OpenVPN UDP Client / LAN Traffic.

    Scheduled Pinned Locked Moved NAT
    5 Posts 2 Posters 553 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pluhdl
      last edited by

      Preamble/Whole Picture:

      I recently got my hands on a decommissioned Sophos XG86 and reflashed it with pfSense and it has been working great. I have installed this behind my ISP modem/router/ap.

      After a few weeks of messing around in my lab I decided that I wanted to upgrade the switch I was using to an 8 port POE+ managed switch. This would allow several benefits for my home lab setup one being I could start to segment my traffic.

      The new switch just came in and I have successfully configured the VLAN [tag3] on the switch and pfSense. Next, I successfully installed NORDVPN OpenVPN UDP Client and pointed only the VLAN to NordVPN.

      Now this is where I am spinning my wheels and I know I am overlooking something simple. I cannot access any LAN resources by IP or FQDN when the NordVPN interface is enabled. I think this is probably because my pfSense is sending local traffic down the VPN. But hey -- im stupid.

      TL;DR: After setting up NordVPN as OpenVPN Client VLAN resources become unavailable.

      Interface Configurations:

      Interface: WAN
      IP Configuration: DHCP

      Interface: LAN
      IP Configuration: STATIC IP: 10.3.10.1/25
      DHCP SCOPE: 10.3.10.2 - 10.3.10.10

      Interface: VLAN
      IP Configuration: STATIC IP: 10.3.10.129/28
      DHCP SCOPE: 10.3.10.130 - 10.3.10.131

      Firewall Rules:

      LAN:
      LAN Rules

      VLAN:
      VLAN Rules

      NORDVPN:
      NORDVPN Rules

      Firewall NAT Rules:
      NAT Rules

      Be the first contestant on: Why am I dumb today?

      NogBadTheBadN 1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad @pluhdl
        last edited by NogBadTheBad

        @pluhdl Disable pull routes in the nord vpn settings.

        BTW you can drag and drop your screenshots directly into your forum message no need to link them.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        P 1 Reply Last reply Reply Quote 0
        • P
          pluhdl @NogBadTheBad
          last edited by

          @NogBadTheBad

          Capture.PNG

          Unfortunately, this did not fix the issue.

          NogBadTheBadN 1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad @pluhdl
            last edited by NogBadTheBad

            @pluhdl Ah it’s normally the answer.

            It’s not a subnet overlap is it, nord hand out 10.x.x.x address space.

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            P 1 Reply Last reply Reply Quote 0
            • P
              pluhdl @NogBadTheBad
              last edited by

              @NogBadTheBad

              OpenVPN Client.PNG

              The local address in the screenshot is the isp router's lan network.
              The virtual address is 10.100.0.2. I am assuming its a /24 network (10.100.0.1 - 10.100.0.254). If it is then there should be no overlap of network ip ranges.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.