<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Route external OpenVPN IP(s) to DMZ]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">I already posted this question in the German support forum, but I couldn't solve the problem yet. We are using an external VPN provider to get one (later multiple) static IPv4 addresses. We configured the connection as OpenVPN client and this is working absolutely fine. Connection is working and we created a new interface "PTYOPENVPN" so that we can route the traffic to a host in our DMZ network. What we have done so far:</p>
<p dir="auto">Configured a 1:1 NAT for the external VPN IP:</p>
<p dir="auto"><img src="http://fs1.directupload.net/images/150911/vfnrlphp.png" alt="" class=" img-fluid img-markdown" /></p>
<p dir="auto">Configured the firewall rules for the new interface:</p>
<p dir="auto"><img src="http://fs2.directupload.net/images/150911/7b57boxi.png" alt="" class=" img-fluid img-markdown" /></p>
<p dir="auto">(192.168.1.5 is the host in the DMZ network)</p>
<p dir="auto">Configured the DMZ rules so that the traffic from 192.168.1.5 goes trough the VPN-Gateway address:</p>
<p dir="auto"><img src="http://fs2.directupload.net/images/150911/vqlzlokw.png" alt="" class=" img-fluid img-markdown" /></p>
<p dir="auto">The DMZ-host 192.168.1.5 is now using the external VPN-IP for outgoing connections. But the trouble begins with incoming connects to the VPN-IP: The packets go trough the firewall and are reaching the DMZ-host, the host responds but this packet never goes through the VPN-Connection.</p>
<p dir="auto">Packet capture of an ICMP request, PTYOPENVPN interface:</p>
<pre><code>
14:16:26.260278 IP 91.X.X.X &gt; 46.X.X.X: ICMP echo request, id 3064, seq 1, length 64
14:16:26.286193 IP 87.X.X.X &gt; 46.X.X.X: ICMP host 91.X.X.X unreachable - admin prohibited filter, length 36
14:16:27.298591 IP 91.X.X.X &gt; 46.X.X.X: ICMP echo request, id 3064, seq 2, length 64
14:16:27.364441 IP 87.X.X.X &gt; 46.X.X.X: ICMP host 91.X.X.X unreachable - admin prohibited filter, length 36

</code></pre>
<p dir="auto">Packet capture of an ICMP request, DMZ interface:</p>
<pre><code>
14:15:07.886133 IP 91.X.X.X &gt; 192.168.1.5: ICMP echo request, id 3058, seq 1, length 64
14:15:07.886515 IP 192.168.1.5 &gt; 91.X.X.X: ICMP echo reply, id 3058, seq 1, length 64
14:15:07.912525 IP 87.X.X.X &gt; 192.168.1.5: ICMP host 91.X.X.X unreachable - admin prohibited filter, length 36
14:15:08.921498 IP 91.X.X.X &gt; 192.168.1.5: ICMP echo request, id 3058, seq 2, length 64
14:15:08.921893 IP 192.168.1.5 &gt; 91.X.X.X: ICMP echo reply, id 3058, seq 2, length 64
14:15:08.981996 IP 87.X.X.X &gt; 192.168.1.5: ICMP host 91.X.X.X unreachable - admin prohibited filter, length 36

</code></pre>
<p dir="auto">tcpdump on DMZ-Host:</p>
<pre><code>
15:36:25.208405 IP 91.X.X.X &gt; 192.168.1.5: ICMP echo request, id 3917, seq 631, length 64
15:36:25.208724 IP 192.168.1.5 &gt; 91.X.X.X: ICMP echo reply, id 3917, seq 631, length 64
15:36:26.020968 IP 91.X.X.X &gt; 192.168.1.5: ICMP echo request, id 3982, seq 358, length 64
15:36:26.021333 IP 192.168.1.5 &gt; 91.X.X.X: ICMP echo reply, id 3982, seq 358, length 64
15:36:26.047909 IP 87.X.X.X &gt; 192.168.1.5: ICMP host 91.X.X.X unreachable - admin prohibited filter, length 36

</code></pre>
<p dir="auto">91.X.X.X: external Host which starts the ping<br />
192.168.1.5: Internal DMZ-Host<br />
46.X.X.X: static VPN-IP<br />
87.X.X.X: seems to be the next hop (router) from our provider, connected on WAN interface</p>
<p dir="auto">We never got packets from 46.X.X.X back to 91.X.X.X through the VPN interface. I already searched the forum for similar problems, but I only found topics related on using the VPN tunnel for all (or part of) the LAN/DMZ network, which is already working for us. What I'm trying to do (easy example):</p>
<p dir="auto">Request:<br />
External Host -&gt; Port 80 on static VPN-IP -&gt; Port 80 on DMZ-Host 192.168.1.X<br />
Response:<br />
DMZ-Host Reply -&gt; VPN -&gt; External Host</p>
<p dir="auto">I guess that I only need to change some of the existing configuration - any help would be greatly appreciated :-)</p>
]]></description><link>https://forum.netgate.com/topic/89009/route-external-openvpn-ip-s-to-dmz</link><generator>RSS for Node</generator><lastBuildDate>Sat, 18 Jul 2026 14:54:45 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/89009.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 12 Sep 2015 21:37:50 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Route external OpenVPN IP(s) to DMZ on Thu, 31 Mar 2016 03:11:52 GMT]]></title><description><![CDATA[<p dir="auto">Did you ever get this working?  This is incredibly similar to something I'm looking to do and have not had much luck with it.</p>
]]></description><link>https://forum.netgate.com/post/611978</link><guid isPermaLink="true">https://forum.netgate.com/post/611978</guid><dc:creator><![CDATA[sporkme]]></dc:creator><pubDate>Thu, 31 Mar 2016 03:11:52 GMT</pubDate></item></channel></rss>