Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVpn client ip arp issues at destination.

    Scheduled Pinned Locked Moved OpenVPN
    3 Posts 2 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      will
      last edited by

      I have set up a functioning open vpn connection.
      I can ping the gateway on that subnet.
      When i try to contact the LAN subnet the traffic is routed through, and i can see it exiting the LAN interface, however, the destination host keeps sending arp requests for the vpn clients mac address, and the pfsense box does not respond appropriately.
      Here is a example:
      03:23:45.808512 ARP, Request who-has 10.103.103.6 tell 10.103.0.8, length 46
      03:23:46.801360 IP 10.103.103.6 > 10.103.0.8: ICMP echo request, id 65150, seq 4826, length 64
      03:23:46.808540 ARP, Request who-has 10.103.103.6 tell 10.103.0.8, length 46
      03:23:47.256334 STP 802.1s, Rapid STP, CIST Flags [Learn, Forward, Agreement]
      03:23:47.803066 IP 10.103.103.6 > 10.103.0.8: ICMP echo request, id 65150, seq 4827, length 64
      03:23:47.808527 ARP, Request who-has 10.103.103.6 tell 10.103.0.8, length 46

      Any ideas whats going on?
      Any advice would be much appreciated!

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        What is the subnet on this client? What should it be?
        If you're trying to connect via a routed network it is probably something smaller than a /16 (is it a /24?)
        however since the client tries to resolve locally this means it's subnet is set to /16 or bigger.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • W
          will
          last edited by

          Fixed it by enabling arp proxing for the the /24 vpn subnet.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.