OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.1 Legacy Series »
  • OpenVPN CSO only works for "default tunnel network"
« previous next »
  • Print
Pages: [1]

Author Topic: OpenVPN CSO only works for "default tunnel network"  (Read 2588 times)

jonakarl

  • Newbie
  • *
  • Posts: 6
  • Karma: 0
    • View Profile
OpenVPN CSO only works for "default tunnel network"
« on: March 23, 2017, 04:23:34 pm »
Hi,

I have multiple VLAN/subnets (one subnet per vlan), only certified personel should have access to the mgmt subnets.
I have a problem with cso where I get no traffic through the firewall to my internal lan when using a different tunnel network from the one I specify on the server page. I had this working in pfsense but I cannot get it working in opnsense.

Current setup:
I have two openvpn servers, one for admins and one for clients, "user" tunnel network is 10.0.8.0/24 and admin uses 10.0.10.0/24.
I block all outgoing traffic to the admin lans from 10.0.8.0/24 on the openvpn interface.
This works but is cumbersome.

What I would like to have:
1 openvpn server and use cso to put the admin personal on a different tunnel network (ie 10.0.10.0/24) so I can filter this in the firewall later.

The cso works to the extent that when I connect with a user that matches the cso, I get 10.0.10.1 as gateway  (strangely also a route to 10.0.8.5). However I cannot ping any ip on the other side of the tunnel (10.0.10.2, my side of the tunnel works).

Any clues on where to start debugging would be helpful since I cannot see anything in the logs. 
Logged

djGrrr

  • Full Member
  • ***
  • Posts: 112
  • Karma: 22
    • View Profile
Re: OpenVPN CSO only works for "default tunnel network"
« Reply #1 on: March 23, 2017, 05:04:29 pm »
I suspect you are missing an outbound NAT rule for the admin network source, you may need to manually add it.
Logged

jonakarl

  • Newbie
  • *
  • Posts: 6
  • Karma: 0
    • View Profile
Re: OpenVPN CSO only works for "default tunnel network"
« Reply #2 on: March 30, 2017, 03:13:43 pm »
Quote from: djGrrr on March 23, 2017, 05:04:29 pm
I suspect you are missing an outbound NAT rule for the admin network source, you may need to manually add it.

I thought so to, however I have added a second openvpn server that uses the exact same subnet range and that added a outbound nat on my WAN interface  (that works). So in theory the nat rules should already be in place (by the second vpn server).

Sorry for the noob questions but I do not fully understand what opnsense does when I run the openvpn wizard. I suspects it adds a "hidden"/virtual interface and add some firewall/nat rules but since I do not know the exact procedure it is very difficult for me to debug this.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.1 Legacy Series »
  • OpenVPN CSO only works for "default tunnel network"
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2