• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[SOLVED]Openvpn connects but no local lan access

Scheduled Pinned Locked Moved OpenVPN
14 Posts 4 Posters 29.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    source
    last edited by Jan 8, 2013, 6:55 PM Jan 6, 2013, 11:41 PM

    Thank you Pfsense Team for an awesome project.  I like pfsense so far. My issue is that I can create  a openvpn connection, authenticates to an ldap server backend, but it does not route to the local network .

    My local net is a 16 bit network example 172.16.0.0/16

    I've had the network that open vpn connects to at 10.10.200.0/24 , 172.16.0.0/16 . 10.10.0.0/16  but i just can see my local servers remotely.  Its kinda pointess and I am not sure what needs to be done to fix this.

    Does anybody have any ideas how to go about resolving this?

    a. authentication works fine, prompts for password, authenticates no issues

    no local area connection access.  \

    I've looked at the firewall rules and see openvpn connection/interface  allow from to . no restrictions

    1 Reply Last reply Reply Quote 0
    • S
      source
      last edited by Jan 7, 2013, 4:57 AM

      ok, i was hoping someone would give me a tip.  I have another clue.

      while on the vpn. i can ping the "inside" interface. But beyond that, i can't see anything else. I think this may be a firewall issue but I am not sure.

      1 Reply Last reply Reply Quote 0
      • H
        heper
        last edited by Jan 7, 2013, 11:38 AM

        its possibly a routing issue …

        draw us a schematic of your setup with the corresponding subnets & show us screenshots of the openvpn server configuration.

        also if using openvpn client on a windows7/vista machine, be sure to click "run as administrator". Otherwise routes will not get added by the client.

        1 Reply Last reply Reply Quote 0
        • S
          source
          last edited by Jan 7, 2013, 3:24 PM

          Im running mac osx mountain lion , ill draw up the info, shortly

          THank you,

          1 Reply Last reply Reply Quote 0
          • S
            source
            last edited by Jan 7, 2013, 5:20 PM Jan 7, 2013, 5:18 PM

            Network layout , openvpn screenshots , and firewall rules.

            Hope this helps, thank you.

            ![demo openvpn layout.png](/public/imported_attachments/1/demo openvpn layout.png)
            ![demo openvpn layout.png_thumb](/public/imported_attachments/1/demo openvpn layout.png_thumb)
            ![Screen Shot 2013-01-07 at 11.15.14 AM.png](/public/imported_attachments/1/Screen Shot 2013-01-07 at 11.15.14 AM.png)
            ![Screen Shot 2013-01-07 at 11.15.14 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2013-01-07 at 11.15.14 AM.png_thumb)
            ![Screen Shot 2013-01-07 at 11.14.41 AM.png](/public/imported_attachments/1/Screen Shot 2013-01-07 at 11.14.41 AM.png)
            ![Screen Shot 2013-01-07 at 11.14.41 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2013-01-07 at 11.14.41 AM.png_thumb)
            ![Screen Shot 2013-01-07 at 11.14.27 AM.png](/public/imported_attachments/1/Screen Shot 2013-01-07 at 11.14.27 AM.png)
            ![Screen Shot 2013-01-07 at 11.14.27 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2013-01-07 at 11.14.27 AM.png_thumb)
            ![Screen Shot 2013-01-07 at 11.24.53 AM.png](/public/imported_attachments/1/Screen Shot 2013-01-07 at 11.24.53 AM.png)
            ![Screen Shot 2013-01-07 at 11.24.53 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2013-01-07 at 11.24.53 AM.png_thumb)

            1 Reply Last reply Reply Quote 0
            • T
              tattoomees
              last edited by Jan 7, 2013, 5:24 PM

              on Advanced add route 172.16.0.0 and your mask etc 255.255.0.0

              1 Reply Last reply Reply Quote 0
              • S
                source
                last edited by Jan 7, 2013, 5:28 PM

                I've done that but it doesnt help.  I will try it again.  Also, i thought that me specifying it in the network portion would do that.

                1 Reply Last reply Reply Quote 0
                • S
                  source
                  last edited by Jan 7, 2013, 5:57 PM Jan 7, 2013, 5:55 PM

                  i added   push "route 172.16.0.0 255.255.0.0";   per the example.  and still no go. It connects great thought… I'm digging the ldap backend authentication.

                  below you'll see the network is there, but strangely its says 172.16 and not 172.16.0.0, not sure if that matters.   The viscosity VPN client for mac showing succesfull connection.  Like i said, I authenticate fine, connect fine, and can get as far as the pfsense lan interface, but beyond that, no.

                  ![Screen Shot 2013-01-07 at 11.57.15 AM.png](/public/imported_attachments/1/Screen Shot 2013-01-07 at 11.57.15 AM.png)
                  ![Screen Shot 2013-01-07 at 11.57.15 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2013-01-07 at 11.57.15 AM.png_thumb)

                  1 Reply Last reply Reply Quote 0
                  • J
                    jimp Rebel Alliance Developer Netgate
                    last edited by Jan 8, 2013, 4:02 PM

                    Is the pfSense firewall to which you connect the default gateway for the lan you're trying to reach?

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • S
                      source
                      last edited by Jan 8, 2013, 6:55 PM

                      dang. thats the problem. Since I've set this up as a demo, to test out pfsense. I have not yet configured it as a gateway. I setup the pfsense as my gw on a local machine and it works, it responds.

                      Thanks for helping me solve this.  I think next would be to setup a route to the 10.0.8.0/24 network on the router.  That should resolve the ping back issue.

                      1 Reply Last reply Reply Quote 0
                      • J
                        jimp Rebel Alliance Developer Netgate
                        last edited by Jan 8, 2013, 7:04 PM

                        Yep, either put the route in the actual gateway, or you can do some outbound NAT on the LAN to make the VPN client traffic appear to originate from the firewall so it would look "local" and thus not requite and special routing. Only downside is that you lose the original client IP in the process, as seen by the target machine. (and it would probably break SMB access)

                        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        1 Reply Last reply Reply Quote 0
                        • S
                          source
                          last edited by Jan 8, 2013, 7:07 PM

                          I there a way to configure pfsense to act as just a vpn appliance, where i don't have to add routing to another device or change the gateway on the local machines?

                          1 Reply Last reply Reply Quote 0
                          • J
                            jimp Rebel Alliance Developer Netgate
                            last edited by Jan 8, 2013, 7:09 PM

                            Only by adding the NAT I mentioned. Otherwise you need routes somewhere.

                            (Or an ugly tap bridge VPN that drops clients into the LAN subnet with LAN IPs…)

                            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                            Need help fast? Netgate Global Support!

                            Do not Chat/PM for help!

                            1 Reply Last reply Reply Quote 0
                            • S
                              source
                              last edited by Jan 8, 2013, 7:20 PM

                              Thanks again, you are my hero!

                              1 Reply Last reply Reply Quote 0
                              • H hillblock referenced this topic on Mar 24, 2025, 8:13 PM
                              5 out of 14
                              • First post
                                5/14
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                This community forum collects and processes your personal information.
                                consent.not_received