Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Problems with blocked TUNx

    OpenVPN
    2
    13
    4536
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sh_man last edited by

      I have three openvpn's, one road warrior and two site to site being used to support two temporary offices at an event we are running for the next month.

      At the moment the two sites are running 1.0.1-SNAPSHOT-02-09-2007 on LiveCD and floppy and the main office is running 1.0.1-SNAPSHOT-03-08-2007 on harddisk - this is to get around the problem of port 1194 being "taken" by the check_reload_status thing.

      Both sites are set up the same - as far as I can tell. I can get openVPN running on both sites and get into the main office.

      On rebooting a temp site firewall I often get firewall logs saying that tun0 has blocked traffic. Usually editing a firewall rule, making no changes, saving and applying gets things moving. A pain but at least it works.

      I now have the following situation. Both are connecting in OK and both sites can get to the main office network. I can reach one remote site without problems but the other give me tunx blocked messages in the log. I have tried remote desktop and ping and got the following logs:-

      Mar 14 15:10:25 TUN1 192.168.1.17:2806 192.168.180.34:3389 TCP
      Mar 14 15:10:22 TUN1 192.168.1.17:2806 192.168.180.34:3389 TCP
      Mar 14 15:08:21 TUN1 192.168.1.17 192.168.180.1 ICMP
      Mar 14 15:08:16 TUN1 192.168.1.17 192.168.180.1 ICMP

      Having looked elsewhere on the forum, I looked in the /tmp/rules.debug and found the following rules - but not one to let the tun1 traffic out.

      pass in quick on tun1 all keep state label "let out anything from firewall host itself openvpn"
      pass out quick on tun2 all keep state label "let out anything from firewall host itself openvpn"
      pass in quick on tun2 all keep state label "let out anything from firewall host itself openvpn"

      How can I get this rule in there reliably. :)

      1 Reply Last reply Reply Quote 0
      • S
        sullrich last edited by

        This doesnt make much sense since the rules are present.

        Try clicking on the red x to the left of the block item and let pfSense tell you which rule is blocking the traffic and report back.

        Also try this from a shell:

        pfctl -sr | grep tun

        1 Reply Last reply Reply Quote 0
        • S
          sh_man last edited by

          The block is the default block all rule.

          I think that there should be a rule like this:-

          pass out quick on tun1 all keep state label "let out anything from firewall host itself openvpn"

          but it does not appear to have been created - it wasn't in the post 'cos it wasn't in the rules.debug file or when I ran the command line.

          1 Reply Last reply Reply Quote 0
          • S
            sullrich last edited by

            Try this after a reboot from a shell:

            /etc/rc.filter_configure_sync

            Then check to see if the rule is loaded.

            1 Reply Last reply Reply Quote 0
            • S
              sh_man last edited by

              Tried that and everything appears to be the same - the tun2 has an in and out rule but the tun1 only has an in rule

              1 Reply Last reply Reply Quote 0
              • S
                sullrich last edited by

                Check your logs, do you see

                Not adding default pass in rule for interface $friendlytunif - tun{$x} with a gateway

                1 Reply Last reply Reply Quote 0
                • S
                  sullrich last edited by

                  Just commited a change.  Please try a snapshot about an hour from now.

                  1 Reply Last reply Reply Quote 0
                  • S
                    sh_man last edited by

                    Cheers - and thanks for all you do - I certainly could not do my job without it.

                    Will have to wait till morning - its 10:30pm here and I'm sat on the sofa watching CSI and sort of working!

                    1 Reply Last reply Reply Quote 0
                    • S
                      sh_man last edited by

                      Will need to do a little more testing when I get to work - the OpenVPN that I need to test is not currently up!

                      However, the rules do not appear to have changed.

                      Having had a quick look, if the time on the forum matches the time on the snapshot server there has not been a snapshot build since you commited your change. will keep my eye on it and get the next build when it appears.

                      1 Reply Last reply Reply Quote 0
                      • S
                        sh_man last edited by

                        Done some more testing and still the same - so I guess I have not got a snapshot with the changes in.

                        1 Reply Last reply Reply Quote 0
                        • S
                          sullrich last edited by

                          Snapshots where not building over night which was my fault.  They should be building now.

                          1 Reply Last reply Reply Quote 0
                          • S
                            sh_man last edited by

                            Cheers - just upgraded to it and it does the job. Thanks

                            1 Reply Last reply Reply Quote 0
                            • S
                              sullrich last edited by

                              Yay!  Thanks for reporting back.

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post