OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • MultiWAN / VPN on VLAN?
« previous next »
  • Print
Pages: [1] 2

Author Topic: MultiWAN / VPN on VLAN?  (Read 7066 times)

+DS_DV+

  • Newbie
  • *
  • Posts: 32
  • Karma: 0
    • View Profile
MultiWAN / VPN on VLAN?
« on: September 10, 2018, 10:23:32 am »
Hello OPNSense Community,

since a week i try to figure out ho i can get my oVPN client 'bound' to a VPN.
The VPN is succesfully set up (but when its started all internet is gone).

I followed several tutorials like:
https://philsheets.me/blog/multi-vlan-vpn-endpoint-pfsense-network/
https://forum.opnsense.org/index.php?topic=4979.0

since it also has the VPN boutn to a VLAN and other traffic to other networks.

my goal is just that the VPN is reachable through a VLAN (lets call it ID10) and rest of the traffic goes to wan.

Can someone help me here?
My trouble points seem to be the gateway and routing. The Firewallrules look ok so far.

with kind regards
+DS_DV+

PS: if someone would be willing to visit my TeamSPeak a/o TeamViewer i would gladly spend some of my students BAföG-money :)
« Last Edit: September 11, 2018, 01:50:22 pm by +DS_DV+ »
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6293
  • Karma: 432
    • View Profile
Re: MultiWAN / VPN on VLAN?
« Reply #1 on: September 10, 2018, 11:22:48 am »
Can you draw a small picture of your infrastructure and what you want to achieve? Also with IP addresses and traffic flows ...
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

+DS_DV+

  • Newbie
  • *
  • Posts: 32
  • Karma: 0
    • View Profile
Re: MultiWAN / VPN on VLAN?
« Reply #2 on: September 11, 2018, 12:10:18 pm »
Quote from: mimugmail on September 10, 2018, 11:22:48 am
Can you draw a small picture of your infrastructure and what you want to achieve? Also with IP addresses and traffic flows ...



Sorry for the delay.
i tried to draw an overview
« Last Edit: September 11, 2018, 08:26:24 pm by +DS_DV+ »
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6293
  • Karma: 432
    • View Profile
Re: MultiWAN / VPN on VLAN?
« Reply #3 on: September 12, 2018, 06:21:28 am »
Ok, understand the network, you talked about VLAN10. In this picture VLAN10 is your Wifi?
Do you want to connect with OpenVPN via WAN or from Wifi?
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

+DS_DV+

  • Newbie
  • *
  • Posts: 32
  • Karma: 0
    • View Profile
Re: MultiWAN / VPN on VLAN?
« Reply #4 on: September 12, 2018, 09:15:38 am »
Quote from: mimugmail on September 12, 2018, 06:21:28 am
Ok, understand the network, you talked about VLAN10. In this picture VLAN10 is your Wifi?
Do you want to connect with OpenVPN via WAN or from Wifi?

Yes. But after making this picture i thihnk it would be better to put the whole VLAN 50 into the VPN.
Afterwards i can always add 10 if i want right?

Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6293
  • Karma: 432
    • View Profile
Re: MultiWAN / VPN on VLAN?
« Reply #5 on: September 12, 2018, 09:25:13 am »
Yes, but to avoid problems in future you should always use networks (Layer 3) to include to a VPN and not name it by VLAN (Layer 2) which isn't possible. :)
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

+DS_DV+

  • Newbie
  • *
  • Posts: 32
  • Karma: 0
    • View Profile
Re: MultiWAN / VPN on VLAN?
« Reply #6 on: September 12, 2018, 10:31:24 am »
Quote from: mimugmail on September 12, 2018, 09:25:13 am
Yes, but to avoid problems in future you should always use networks (Layer 3) to include to a VPN and not name it by VLAN (Layer 2) which isn't possible. :)

ok - will do :)

so how can i fix / set up what i desire?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6293
  • Karma: 432
    • View Profile
Re: MultiWAN / VPN on VLAN?
« Reply #7 on: September 12, 2018, 12:19:36 pm »
Can you Post a screenshot of OpenVPN server config?
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

+DS_DV+

  • Newbie
  • *
  • Posts: 32
  • Karma: 0
    • View Profile
Re: MultiWAN / VPN on VLAN?
« Reply #8 on: September 12, 2018, 01:32:23 pm »
its a client.

i think it may work as a 2nd wan?
if its connected it looks like in the attachment.
but when its connected i cant reach the internet seems to be unreachable from any point in the lan.


an OVPN server will be the last step in the plan of building my home network.
[best would be if Client -> VPN (to home) -> LAN -> VPN (the one we are setting up right now) -> internet would work] - but for now i would be happy if my desired VLAN would use the VPN to get to the internet :)
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6293
  • Karma: 432
    • View Profile
Re: MultiWAN / VPN on VLAN?
« Reply #9 on: September 12, 2018, 04:05:03 pm »
Sorry, I dont get it. OPN is your WAN Firewall and should act as server or client?
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

+DS_DV+

  • Newbie
  • *
  • Posts: 32
  • Karma: 0
    • View Profile
Re: MultiWAN / VPN on VLAN?
« Reply #10 on: September 12, 2018, 04:22:23 pm »
Quote from: mimugmail on September 12, 2018, 04:05:03 pm
Sorry, I dont get it. OPN is your WAN Firewall and should act as server or client?

the end goal is that it does both.

at the moment it just should act as a client.
but only specific networks / vlans should go through the (client)VPN.


later when everything is set up i want for example my laptop from sisters house to conect to the OPNsense firewall (acting as a VPN server) because i want to access the LAN (home) an from there exit to the internet using the (client) VPN of the firewall.

//EDIT1:  i drew a picture :)

The external stuff is not importent right now. For now i just want the VPN Client stuff to run ^^
« Last Edit: September 12, 2018, 04:43:43 pm by +DS_DV+ »
Logged

+DS_DV+

  • Newbie
  • *
  • Posts: 32
  • Karma: 0
    • View Profile
Re: MultiWAN / VPN on VLAN?
« Reply #11 on: September 14, 2018, 10:52:35 am »


can anybody help? i cant pay much but i would appreciate it very much!
i have a feeling its just fw-rules and gateway setups
Logged

namezero111111

  • Jr. Member
  • **
  • Posts: 94
  • Karma: 10
    • View Profile
Re: MultiWAN / VPN on VLAN?
« Reply #12 on: September 14, 2018, 01:01:47 pm »
Given that all interfaces are setup and this comes down only to routing, I would recommend to set the default gateway to WAN and use policy-based routing to route the ip ranges on vlan 50 through the VPN provider gateway.
Logged

+DS_DV+

  • Newbie
  • *
  • Posts: 32
  • Karma: 0
    • View Profile
Re: MultiWAN / VPN on VLAN?
« Reply #13 on: September 14, 2018, 02:29:19 pm »
Quote from: namezero111111 on September 14, 2018, 01:01:47 pm
Given that all interfaces are setup and this comes down only to routing, I would recommend to set the default gateway to WAN and use policy-based routing to route the ip ranges on vlan 50 through the VPN provider gateway.

hey thanks for the hint.
i tried so many things in the last week (my holiday) but seems i cant get it working :(
would you mind helping me via TeamViewer and TeamSpeak?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6293
  • Karma: 432
    • View Profile
Re: MultiWAN / VPN on VLAN?
« Reply #14 on: September 14, 2018, 05:36:34 pm »
Monday, 9:30am IRC
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

  • Print
Pages: [1] 2
« previous next »
  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • MultiWAN / VPN on VLAN?
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2