• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to allow openvpn client access to a IPSEC vpn

Scheduled Pinned Locked Moved OpenVPN
3 Posts 3 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    Paddy
    last edited by Feb 28, 2014, 2:03 PM

    I have a remote user the connects to us via OpenVPN. I also have a site-to-site IPSEC vpn from our local subnet to a remote site.

    I now need to allow the OpenVPN client access to the IPSEC vpn so that he can connect to our local subnet but also our remote site.

    Previously when we used PPTP it was no problem because the user was assigned a IP on our local subnet when connected.

    Could someone point me in the right direction?

    Thanks

    1 Reply Last reply Reply Quote 0
    • G
      Gob
      last edited by Feb 28, 2014, 9:04 PM

      You need to ensure your IPSEC tunnel also has a phase2 entry for your OpenVPN Client subnet (at both ends of your IPSEC tunnel).

      You also need to ensure the OpenVPN client has a route to the remote subnet. You can do this by adding a line in the configuration options on the Client Export page. For example, if the remote site is 192.168.4.0/24:

      push "route 192.168.4.0 255.255.255.0";

      That's the theory, but in practice I have been struggling getting the client to automatically create the route on Windows 8.
      If you manually create the route on the client it works fine.

      If I fix one more thing than I break in a day, it's a good day!

      1 Reply Last reply Reply Quote 1
      • P
        phil.davis
        last edited by Mar 1, 2014, 7:44 AM

        On 2.1 and later you just put a comma-separated list of subnets in "Local Network/s" and then the OpenVPN server tell the client about routes to all those. There is no need to use the Advanced box.

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received