Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cannot reach LAN network via OpenVPN tun

    Scheduled Pinned Locked Moved OpenVPN
    38 Posts 7 Posters 15.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      doktornotor Banned
      last edited by

      Let me state again: Tick the Topology checkbox, disconnect, reconnect and try again.

      1 Reply Last reply Reply Quote 0
      • E
        esink
        last edited by

        @doktornotor:

        Let me state again: Tick the Topology checkbox, disconnect, reconnect and try again.

        I already did. It didn't work

        1 Reply Last reply Reply Quote 0
        • D
          doktornotor Banned
          last edited by

          @esink:

          I already did. It didn't work

          On another note, NetBIOS is disabled by default as well (yet another checkbox). And on yet another note, turn off the Windows firewall before doing any of these tests.

          1 Reply Last reply Reply Quote 0
          • E
            esink
            last edited by

            @doktornotor:

            @esink:

            I already did. It didn't work

            On another note, NetBIOS is disabled by default as well (yet another checkbox). And on yet another note, turn off the Windows firewall before doing any of these tests.

            okay, but this doesn't solve that I can't PING THE GATEWAY.

            My tests include

            1. attempt to reach a windows share by IP - Server 2012 definitely has this and hosts on the LAN are definitely able to reach it
            2. RDP to the machines - RDP is DEFINITELY allowed. if I port forward over WAN I can RDP to the machines
            3. ping the LAN gateway - hosts on the LAN are able to do this.
            4. ping the machines - hosts on LAN are able to do this.
            1 Reply Last reply Reply Quote 0
            • K
              kejianshi
              last edited by

              And you are re-exporting and reinstalling the client config after you make changes to openvpn server?

              1 Reply Last reply Reply Quote 0
              • D
                doktornotor Banned
                last edited by

                As said above. And in addition:

                Simplify the thing for basic testing so that stupid things like "I'm not even allowing DNS over the vpn" are out of the way! Get the crappy Windows firewalls out of way as well. Make the things wide open UNTIL you can get basic things working. You can tighten things up AFTER that. Noone's interested in debugging something for days only to turn out that the issue is totally unrelated to pfSense. (And on that note, getting a sane OVPN client for testing would help as well. No, W8 is not one.)

                1 Reply Last reply Reply Quote 0
                • E
                  esink
                  last edited by

                  @doktornotor:

                  As said above. And in addition:

                  Simplify the thing for basic testing so that stupid things like "I'm not even allowing DNS over the vpn" are out of the way! Get the crappy Windows firewalls out of way as well. Make the things wide open UNTIL you can get basic things working. You can tighten things up AFTER that. Noone's interested in debugging something for days only to turn out that the issue is totally unrelated to pfSense. (And on that note, getting a sane OVPN client for testing would help as well. No, W8 is not one.)

                  I feel like I should really worry about being able to ping the LAN gateway before worrying about anything else, but fine firewalls are off.

                  I have a win 7 client too. same deal.

                  1 Reply Last reply Reply Quote 0
                  • P
                    phil.davis
                    last edited by

                    I just got a road warrior OpenVPN going on my Win8 laptop again. It uses tunnel 10.50.80.0/24 and I get allocated 10.4950.80.4/30 (server .5 client .6) OpenVPN manages these IP addresses inside the tunnel.
                    I can ping 10.50.80.1 but NOT 10.50.80.5
                    So I suggest you try ping 172.16.1.1 - that should work, not the .5 IP.

                    As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                    If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                    1 Reply Last reply Reply Quote 0
                    • E
                      esink
                      last edited by

                      @phil.davis:

                      I just got a road warrior OpenVPN going on my Win8 laptop again. It uses tunnel 10.50.80.0/24 and I get allocated 10.49.80.4/30 (server .5 client .6) OpenVPN manages these IP addresses inside the tunnel.
                      I can ping 10.50.80.1 but NOT 10.50.80.5
                      So I suggest you try ping 172.16.1.1 - that should work, not the .5 IP.

                      I cannot ping 172.16.1.1

                      1 Reply Last reply Reply Quote 0
                      • P
                        phil.davis
                        last edited by

                        I cannot ping 172.16.1.1

                        It really does sound like a firewall rule somewhere is not allowing this. Look in the firewall log when you try to ping, is anything being logged? Do you have any floating rules that would match this ping?
                        If you are not using the OPENVPNTAP interface assignment for anything you intended, then I would remove it and go back to having just the generic OpenVPN tab - that will remove one complication.
                        Post some actual screenshots of rules when you are feeling really stuck.

                        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                        1 Reply Last reply Reply Quote 0
                        • E
                          esink
                          last edited by

                          @phil.davis:

                          I cannot ping 172.16.1.1

                          It really does sound like a firewall rule somewhere is not allowing this. Look in the firewall log when you try to ping, is anything being logged? Do you have any floating rules that would match this ping?
                          If you are not using the OPENVPNTAP interface assignment for anything you intended, then I would remove it and go back to having just the generic OpenVPN tab - that will remove one complication.
                          Post some actual screenshots of rules when you are feeling really stuck.

                          I already have posted my firewall rules. The openvpn tab of rules just has 1 any any rule.

                          1 Reply Last reply Reply Quote 0
                          • E
                            esink
                            last edited by

                            Well there has to be a firewall rule messed up somewhere. I just tried to ping my LAN network from the PfSense box's OpenVPN interface and it can only hit the gateway, not any other host on the LAN.

                            What firewall rules are necessary for this to work? I already ahve a rule on the OpenVPN tab that says allow allow anything to LAN

                            ![9-20-2013 7-41-29 AM.png_thumb](/public/imported_attachments/1/9-20-2013 7-41-29 AM.png_thumb)
                            ![9-20-2013 7-41-29 AM.png](/public/imported_attachments/1/9-20-2013 7-41-29 AM.png)
                            Openvpnrule.png
                            Openvpnrule.png_thumb
                            lanping.png
                            lanping.png_thumb
                            vpnping.png
                            vpnping.png_thumb

                            1 Reply Last reply Reply Quote 0
                            • E
                              esink
                              last edited by

                              so this is really starting to piss me off. I just said fuck it and deleted the VON server and all the certs and firewall rules that were associated with it, and went through the wizard to set up the new OpenVPN instance, and I followed a youtube vid to the T.

                              http://www.youtube.com/watch?v=VdAHVSTl1ys

                              the wizard created the firewall rules for me so I KNOW they're right….

                              STILL I cannot ping the other end of the tunnel, nor the LAN gateway, nor anything on the LAN. I am now testing on a different PC (win 7) on a completely different network than the original PC (to rule out anything inbetween me and the PfSense box.)

                              1 Reply Last reply Reply Quote 0
                              • D
                                doktornotor Banned
                                last edited by

                                Maybe you should just try different test than "ping". Seriously, this whole thing works out of the box in five minutes, no need to waste days. If you screwed so much that it's not fixable, go reinstall from scratch, incl. all you rules.

                                1 Reply Last reply Reply Quote 0
                                • E
                                  esink
                                  last edited by

                                  @doktornotor:

                                  Maybe you should just try different test than "ping". Seriously, this whole thing works out of the box in five minutes, no need to waste days. If you screwed so much that it's not fixable, go reinstall from scratch, incl. all you rules.

                                  yeah I agree. I have spare NetGate boxes here at work. I'm going to make one from scratch with all the rules I need, and import the xml to my box at home after a factory reset. I will report back with results.

                                  1 Reply Last reply Reply Quote 0
                                  • DerelictD
                                    Derelict LAYER 8 Netgate
                                    last edited by

                                    I am having exactly this same problem trying to replace an ipsec site to site with OpenVPN (PKI) site to site.  The tunnel comes up as expected but traffic is not passing between LANs.

                                    (Sort of solved - see bottom of post)

                                    I am following the "Site to Site Example Configuration (SSL/TLS)" section in the 2.1 book draft.

                                    The routing tables look like the proper routes are being pushed.

                                    Interestingly, I would expect to be able to ping the remote tunnel addresses but I can't.

                                    Home (192.168.223.0/24) <–-> pfSense 2.1 (client) <---> Internet <---> pfSense 2.1 (server) <---> 172.22.81.0/24 (Work)

                                    Tunnel network on server set to 172.22.83.0/24

                                    I've tried to find firewall block log entries and have come up empty.

                                    In the server config I have the following:

                                    IPv4 Tunnel Network: 172.22.83.0/24

                                    IPv4 Local Network(s): 172.22.81.0/24

                                    Advanced:
                                    route 192.168.223.0 255.255.255.0;
                                    push "route 192.168.223.0 255.255.255.0";

                                    I have the following routes in the server's route table:
                                    172.22.83.0/24    172.22.83.2        UGS        0        5 ovpns2
                                    172.22.83.1        link#15            UHS        0        0    lo0
                                    172.22.83.2        link#15            UH          0        0 ovpns2
                                    192.168.223.0/24  172.22.83.2        UGS        0      66 ovpns2

                                    In the client-specific overrides for the client CN I have:
                                    iroute 192.168.223.0 255.255.255.0;

                                    I have the following routes in the client's route table:
                                    172.22.81.0/24    172.22.83.5        UGS        0      19 ovpnc1
                                    172.22.83.1/32    172.22.83.5        UGS        0        8 ovpnc1
                                    172.22.83.5        link#13            UH          0        0 ovpnc1

                                    I have any any firewall rules in both sites' OpenVPN firewall rules.

                                    WAIT HOLD EVERYTHING:

                                    I had a custom Multi-WAN WANGROUP gateway (since I have Cable and DSL modems at home) that redirected all traffic from the client's LAN to Gateway WANGROUP.  I changed that to the default gateway and traffic started passing.  Posting everything since it might help someone else.

                                    Any pointers to the proper config for this instance?

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    1 Reply Last reply Reply Quote 0
                                    • A
                                      abidkhanhk
                                      last edited by

                                      @kejianshi:

                                      Yeah - But for windows8 there is an extra hitch sometimes:

                                      Look at very bottom of this page.

                                      http://www.vpntutorials.com/tutorials/openvpn-client-setup-tutorial-for-windows-8/

                                      I am having similar issue, even though CMAK is on and the route method exe added to the config file but unable to get IP from Server.

                                      did anyone have any luck on this? maybe can their config example. thanks

                                      1 Reply Last reply Reply Quote 0
                                      • K
                                        kejianshi
                                        last edited by

                                        I don't know what to say except that openvpn works and is REALLY easy to set up.  I can't guarantee how it will interact with existing firewall rules (meaning you can easily have firewall rule errors).

                                        1 Reply Last reply Reply Quote 0
                                        • DerelictD
                                          Derelict LAYER 8 Netgate
                                          last edited by

                                          Wow.  That post is really n00b.  Thanks for bumping this necrothread. :/

                                          Chattanooga, Tennessee, USA
                                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                          1 Reply Last reply Reply Quote 0
                                          • K
                                            kejianshi
                                            last edited by

                                            haha - Don't mention it.  Anything for you buddy (-;

                                            (No seriously - Don't mention it…  To anyone)

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.