<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[General VPN traffic]]></title><description><![CDATA[<p dir="auto">We have users that need to get vpn traffic out for work. Since I don't know what or who they are connecting to is there a way to pass generic VPN traffic in and out of pfsense. They connect through an access point on the LAN interface of pfsense.</p>
<p dir="auto">Thanks again</p>
<p dir="auto">We have a LAN interface and a WAN interface<br />
DHCP on LAN static IP on WAN, The AP (172.16.50.253) gets addresses from the LAN DHCP pool 172.16.50. - 50.200. We have. Allow any tcp/udp ports 53, 80, 443 to any on the LAN interface. We also have a VPN ports alas group with TCP ports 1723, UDP ports 50, 500 1701 and 4500 on the LAN interface with allow from LAN net to any from VPN alias group to any. The WAN interface has the stock rules. This is a separated network outside of our production network for guest access</p>
]]></description><link>https://forum.netgate.com/topic/90937/general-vpn-traffic</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Jul 2026 07:24:09 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/90937.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 28 Oct 2015 17:37:14 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to General VPN traffic on Wed, 28 Oct 2015 23:51:05 GMT]]></title><description><![CDATA[<p dir="auto">Pass access to the local assets they need if any (DNS, etc)<br />
Reject access to the local assets you want to protect (other local networks, this firewall)<br />
Pass everything else (the internet)</p>
]]></description><link>https://forum.netgate.com/post/580009</link><guid isPermaLink="true">https://forum.netgate.com/post/580009</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Wed, 28 Oct 2015 23:51:05 GMT</pubDate></item><item><title><![CDATA[Reply to General VPN traffic on Wed, 28 Oct 2015 23:48:28 GMT]]></title><description><![CDATA[<p dir="auto">I have a meeting about that tomorrow morning, I think they are just going to let me send it all out. If that is the case would I remove everything and put in the pass from any to any rule on the lan interface.?</p>
]]></description><link>https://forum.netgate.com/post/580008</link><guid isPermaLink="true">https://forum.netgate.com/post/580008</guid><dc:creator><![CDATA[cal2600]]></dc:creator><pubDate>Wed, 28 Oct 2015 23:48:28 GMT</pubDate></item><item><title><![CDATA[Reply to General VPN traffic on Wed, 28 Oct 2015 23:19:55 GMT]]></title><description><![CDATA[<p dir="auto">Why lock down guest access so hard? Just askin'.</p>
]]></description><link>https://forum.netgate.com/post/579996</link><guid isPermaLink="true">https://forum.netgate.com/post/579996</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Wed, 28 Oct 2015 23:19:55 GMT</pubDate></item><item><title><![CDATA[Reply to General VPN traffic on Wed, 28 Oct 2015 23:12:18 GMT]]></title><description><![CDATA[<p dir="auto">Please post screenshots of rules / NAT.<br />
Is the WAN IP a public IP?</p>
<p dir="auto">UDP 500, 4500 should work for most VPNs provided they support NAT-T.  If not you might also need to enable protocol ESP.</p>
]]></description><link>https://forum.netgate.com/post/579992</link><guid isPermaLink="true">https://forum.netgate.com/post/579992</guid><dc:creator><![CDATA[awebster]]></dc:creator><pubDate>Wed, 28 Oct 2015 23:12:18 GMT</pubDate></item><item><title><![CDATA[Reply to General VPN traffic on Wed, 28 Oct 2015 17:58:47 GMT]]></title><description><![CDATA[<p dir="auto">Need way more info to hazard so much as a guess.</p>
]]></description><link>https://forum.netgate.com/post/579944</link><guid isPermaLink="true">https://forum.netgate.com/post/579944</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Wed, 28 Oct 2015 17:58:47 GMT</pubDate></item></channel></rss>