Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN unable to access local network when all traffic routed through IPSec

    Scheduled Pinned Locked Moved OpenVPN
    2 Posts 2 Posters 199 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      karpia8
      last edited by

      Hello guys!
      Recently I implemented some changes to pfSense, specifically:
      I set the remote network as 0.0.0.0/0 in the P2 VPN settings for the IPSec tunnel (between pfSense and other firewall).
      It went fine, and now all traffic from local network is going through the VPN tunnel, so I achieved my goal (I wanted all network traffic from the local subnet on pfSense to the Internet to go through the WAN interface on the firewall on the other side of the IPSec tunnel).

      However, I encountered an issue with OpenVPN. Since the local subnet is reachable from the other side of VPN tunnel, it is unavailable for the OpenVPN clients connecting directly to pfSense. The VPN is connecting, but it is impossible to reach local network.

      I checked packet capture and it seems like there is no response at all from the local network to OpenVPN client. Also I checked logs on the firewall on the other side of VPN tunnel: no logs indicating the connections from OpenVPN clients there.

      On the diagram below I presented the topology. Connection from OpenVPN Client to pfSense is working, but LAN network behind pfSense is unreachable.

      diagram.drawio.png

      Would you be able to support me in this matter?

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @karpia8
        last edited by

        @karpia8
        Is this an OpenVPN access server, where 172.20.20.0/24 is the tunnel network?
        If so I don't expect, that there is any impact due the IPSec settings.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.