Cross-client OpenVPN routing issues on pfSense

  • Hello all,

    I currently have about 15 sites with DD-WRT routers. Each router has it's own subnet (i.e.,, etc), but I've configured each router as an OpenVPN client so that devices on each subnet can communicate with one another (i.e. can ping, and vice-versa). The OpenVPN server is an OpenVPN Access Server hosted in the cloud. This has been working great for months.

    However, I'm now wanting to swap out my DD-WRT boxes for pfSense routers. I've successfully configured pfSense as an OpenVPN client using this post ( as a guide, and I can ping out from behind the pfSense router (i.e. to all of the other clients without any issues. But when attempting to ping the pfSense router from the other clients/subnets, I cannot see it.

    I had the same issue when initially setting up my DD-WRT routers and fixed it by entering the following script into the startup commands:

    iptables -I FORWARD -i br0 -o tun0 -j ACCEPT
    iptables -I FORWARD -i tun0 -o br0 -j ACCEPT

    This script, I think, is the magic that makes it all work, but I don't know how to replicate it on pfSense. To compare, here's my pfSense routing table:

    Destination          Gateway        Flags    Refs  Use    Mtu    Netif
    default      UGS      0      1388  1500    vr1        UGS    0      1154  1500    ovpnc1        link#1            U        0      2071  1500    vr0            link#1            UHS      0      0      16384  lo0            link#6            UH      0      47    16384  lo0        link#9            U        0      5      1500    ovpnc1          link#9            UHS      0      0      16384  lo0        UGS    0      0      1500    ovpnc1        UGS    0      0      1500    ovpnc1    link#2            U        0      134    1500    vr1      link#2            UHS    0      0      16384  lo0

    And here's a working DD-WRT routing table:

    Destination LAN  Subnet Mask      Gateway      Interface        WAN    tun0        WAN    tun0          LAN & WLAN        LAN & WLAN          tun0        tun0          WAN

    Any help getting this working in pfSense would be greatly appreciated!

  • Anyone? If I can provide more information or more clearly state the problem, please let me know.

Log in to reply