Jump to content

This is really starting to PISS me off! Anyway I've configured my pfsense box to be an OpenVPN server. The issues I'm facing is that I cannot reach the LAN side of my network. I can ping my pfsense box but anything else I cannot do. LAN network of my pfsense box is 172.16.105.0 and the tunnel network is 192.168.100.0. I want to access my LAN network. 

 

Please help. :(:( 

 

 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/
Share on other sites

Link to post
Share on other sites

6 minutes ago, Ginz said:

Add a route in your OpenVPN config

I did... 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10302622
Share on other sites

Link to post
Share on other sites

Just now, Ginz said:

Have you added firewall rules allowing traffic between your LAN and your OpenVPN interfaces?

It was done automatically when I configured OpenVPN.. 

 

 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10302627
Share on other sites

Link to post
Share on other sites

12 minutes ago, Ginz said:

Not sure then sorry :S, I run my OpenVPN server on linux

How did you configure yours? I get no default gateway IP address. 

 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10302667
Share on other sites

Link to post
Share on other sites

5 minutes ago, Falconevo said:

Can you screenshot the rules on the OpenVPN firewall tab and your LAN tab, obviously omit any private information you may have on it.

34a439d7a322ddea7683d7cc2c425659.png

 

 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10302816
Share on other sites

Link to post
Share on other sites

I'm assuming you are routing this VPN to the Private subnet?  Can you output the rule set you have on this.

Also if you can provide information about the internal IP ranges on both sides of the tunnel and what you can and can't access when performing a ping between locations.

Please quote or tag me if you need a reply

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10302835
Share on other sites

Link to post
Share on other sites

3 minutes ago, Falconevo said:

I'm assuming you are routing this VPN to the Private subnet?  Can you output the rule set you have on this.

Also if you can provide information about the internal IP ranges on both sides of the tunnel and what you can and can't access when performing a ping between locations.

I can ping the PfSense box but not the LAN IP. 

 

 

This is the IP rules I added:

 

c56b37b5b85eee176a3fe52123ecf93d.png

 

f8e4d0312f5863607ca824c129b60279.png

 

 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10302858
Share on other sites

Link to post
Share on other sites

Ok, can you clarify something for me,


The PfSense Internal subnet is 172.16.105.0/24, what is the IP subnet on the other side of the tunnel?  If the network on the other side of the tunnel is 192.168.100.0/24 then you need to change the IPv4 Tunnel Network to something different like 10.0.8.0/24 which is an alternate subnet for the communication between the virtual tap/tun interfaces on either side of the tunnel.

 

You shouldn't need that additional custom option, its not needed if it is setup correctly, what is the connecting device? Another pfSense box for Site-to-Site or some other router/firewall?

Please quote or tag me if you need a reply

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10302875
Share on other sites

Link to post
Share on other sites

6 minutes ago, Falconevo said:

Ok, can you clarify something for me,


The PfSense Internal subnet is 172.16.105.0/24, what is the IP subnet on the other side of the tunnel?  If the network on the other side of the tunnel is 192.168.100.0/24 then you need to change the IPv4 Tunnel Network to something different like 10.0.8.0/24 which is an alternate subnet for the communication between the virtual tap/tun interfaces on either side of the tunnel.

 

You shouldn't need that additional custom option, its not needed if it is setup correctly, what is the connecting device? Another pfSense box for Site-to-Site or some other router/firewall?

This isn't site-to-site. The is OpenVPN.. I tried the default 10.0.8.0/24 and same thing is happening.. nothing works. :( 

 

My PfSense is the OpenVPN server. 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10302882
Share on other sites

Link to post
Share on other sites

Ok, so you are providing client access rather than site-to-site, you will need to check your firewall rule set on the Private Subnet to allow the traffic from the IP subnet you are handing out to clients.

When you have a client device connected on VPN, what is the internal VPN IP address you receive from the pfSense OpenVPN?

 

I can't understand why you have a NAT rule present on the OpenVPN adapter as this is taken care of by the listener on the WAN port on UDP 1194, so you don't need the NAT forward it will only cause you problems. If you have the OpenVPN set on Interface WAN then you don't need that NAT but you do need a firewall rule to allow 1194 UDP on the WAN side to allow the listen port to be active (you can white list if you don't want it open to the public).


It should look something like this, you can replace the UDP rule for a 'Source' Whitelist if you want to secure it down and not have the VPN end point public.  Remove the NAT as it isn't required for the OpenVPN tunnel.wan.PNG.69f570caebee1ef19a3371f67ce6381e.PNG


VPN Server listener

vpn.PNG.f66fdcd049b03c9d06055dcc33bf8c53.PNG

Please quote or tag me if you need a reply

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10302911
Share on other sites

Link to post
Share on other sites

5 minutes ago, Falconevo said:

Ok, so you are providing client access rather than site-to-site, you will need to check your firewall rule set on the Private Subnet to allow the traffic from the IP subnet you are handing out to clients.

When you have a client device connected on VPN, what is the internal VPN IP address you receive from the pfSense OpenVPN?

 

I can't understand why you have a NAT rule present on the OpenVPN adapter as this is taken care of by the listener on the WAN port on UDP 1194, so you don't need the NAT forward it will only cause you problems. If you have the OpenVPN set on Interface WAN then you don't need that NAT but you do need a firewall rule to allow 1194 UDP on the WAN side to allow the listen port to be active (you can white list if you don't want it open to the public).


It should look something like this, you can replace the UDP rule for a 'Source' Whitelist if you want to secure it down and not have the VPN end point public.  Remove the NAT as it isn't required for the OpenVPN tunnel.


VPN Server listener

 

The IP address that the clients get is from 10.8.0.0 network/ 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10302922
Share on other sites

Link to post
Share on other sites

Just now, Abdul201588 said:

The IP address that the clients get is from 10.8.0.0 network/ 

Remove the NAT from the OpenVPN and setup a rule on the Private Firewall Tab to allow traffic from the VPN network.  Depending on how secure you want it you may not want to use * * * on the firewall rule.

 

Source - OpenVPN Subnet - 10.0.8.0/24

Destination - Private Subnet - 172.16.105.0/24

Rule - what ever you want, maybe use */Any for testing purposes.

Reconnect VPN client and ping the internal IP of the private subnet on pfSense assuming 172.16.105.1?

Please quote or tag me if you need a reply

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10302929
Share on other sites

Link to post
Share on other sites

3 minutes ago, Falconevo said:

Remove the NAT from the OpenVPN and setup a rule on the Private Firewall Tab to allow traffic from the VPN network.  Depending on how secure you want it you may not want to use * * * on the firewall rule.

 

Source - OpenVPN Subnet - 10.0.8.0/24

Destination - Private Subnet - 172.16.105.0/24

Rule - what ever you want, maybe use */Any for testing purposes.

Reconnect VPN client and ping the internal IP of the private subnet on pfSense assuming 172.16.105.1?

Now I can't connect to the VPN... 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10302938
Share on other sites

Link to post
Share on other sites

23 minutes ago, Abdul201588 said:

Now I can't connect to the VPN... 

What interface do you have specified in the OpenVPN configuration?  Did you add the firewall rule on the WAN side like I mentioned earlier on?

 

Things you need;

Correct interface for OpenVPN config (WAN usually)

Rule on WAN interface to allow UDP 1194 (this replaces the rule you had auto generated from the NAT)
Rule on Private Subnet to allow traffic from OpenVPN subnet

Rule on OpenVPN subnet to allow traffic from Private Subnet

Please quote or tag me if you need a reply

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10303002
Share on other sites

Link to post
Share on other sites

4 minutes ago, Falconevo said:

What interface do you have specified in the OpenVPN configuration?  Did you add the firewall rule on the WAN side like I mentioned earlier on?

 

Things you need;

Correct interface for OpenVPN config (WAN usually)

Rule on WAN interface to allow UDP 1194 (this replaces the rule you had auto generated from the NAT)
Rule on Private Subnet to allow traffic from OpenVPN subnet

Rule on OpenVPN subnet to allow traffic from Private Subnet

I gave up. I've got a raspberry Pi3 and I'm going to see if it would work. 

 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10303015
Share on other sites

Link to post
Share on other sites

2 minutes ago, Falconevo said:

lol, it's not a difficult task.  It's a VPN service listener config, then 3 firewall rules.

Meh. I'm having actually issues with it as well. 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10303029
Share on other sites

Link to post
Share on other sites

30 minutes ago, Falconevo said:

If you want to give me temp access via private message, I can take a look for you?

The problem is  the PC itself. It hangs randomly and I have restart it every time. I've tried the Pi3 and it works fine. :)

 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/822240-pfsense-openvpn-issues/#findComment-10303125
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×