Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [Solved] Connections across VPN getting NATed

    OpenVPN
    3
    5
    2.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jterhune
      last edited by

      Here is my setup:

      VPN Server                                       VPN Client
      tun0 (172.27.1.1/24)<–-------------> tun0(172.27.1.2/24)

      LAN (172.16.0.198/19)                        LAN(172.19.2.1/24)
                |
                |
                |
             Router
      int1 172.16.0.2
      int2 192.168.0.0/24

      OpenVPN client and server are connected and share subnet 172.27.1.1 for their link. All static routes are in place and all connections work fine but if a client, 172.19.2.100, pings another client, 192.168.0.180, 192.168.0.180 sees the connection coming from 172.27.1.2. It looks like VPN connections are getting NATed in both directions.

      Is there a way to avoid this? Normally this would all be fine, but I have a NEC VoIP phone I need to connect on 172.19.2.0 to connect to our PBX on 192.168.0.0 and it is VERY pissy about NATing.

      Any advice would be wonderful. If any more information is needed, let me know.

      Thanks!

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        Did you assign the tun interface as OPT?
        Did you create any AoN rules?

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • J
          jterhune
          last edited by

          I assigned both tun interfaces as opt, and made an any/any/all rule for both of them.

          I tried with both automatic outbound NAT and manual with no rules. Both seemed to have the same result.

          1 Reply Last reply Reply Quote 0
          • D
            danswartz
            last edited by

            When you set up the AON rule for the tunnel, did you specify "no NAT"?

            1 Reply Last reply Reply Quote 0
            • J
              jterhune
              last edited by

              Thanks folks, I got it. I feel silly for not figuring that out. Can't wait till my pfSense book gets here, hopefully that will cut down on the forum posts :)

              Thanks again.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.