Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Quickie fix - I Can access local network but I can't access internet.

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 4 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      broknbottle
      last edited by

      I have my pfSense / OpenVPN box setup and I am able to access it using my mac+viscosity (great app btw)  but I recently put the (push "dhcp-option DNS 10.10.x.x";push "redirect-gateway def1") in my custom options.  Now I am able to access the local network that's behind the VPN but I am not able to access the internet anymore, and I am sure it has to do with a firewall rule or forwarding a port but I am not 100% what I am supposed to edit and what parameters are needed.  Also when I use the push "dhcp-option DNS x.x.x.x", does that bypass the network DNS that I am connection from and use my DNS? which in my case is OpenDNS.  Thanks and I appreciate any help / insight!

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        On the pfSense box, switch to Advanced Outbound NAT and add a rule that will NAT your remote OpenVPN IPs to your box's WAN address. That should get it going.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • B
          broknbottle
          last edited by

          Ok I am just posting to confirm and making sure that I did this correctly.

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            Your destination should be any. (The internet is any ;) )

            You need at least another rule with as source your LAN. Otherwise you can reach the internet from the OpenVPN subnet but no longer from the LAN.
            An alternative would be to change the source to any as well, but i don't know if you want to allow that.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • AhnHELA
              AhnHEL
              last edited by

              Should look like this when you're done.

              ![Screen shot 2010-02-12 at 3.35.42 AM.png_thumb](/public/imported_attachments/1/Screen shot 2010-02-12 at 3.35.42 AM.png_thumb)
              ![Screen shot 2010-02-12 at 3.35.42 AM.png](/public/imported_attachments/1/Screen shot 2010-02-12 at 3.35.42 AM.png)

              AhnHEL (Angel)

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.