OPNsense Forum

English Forums => Virtual private networks => Topic started by: RamSense on May 30, 2021, 12:44:31 pm

Title: OpenVPN connect/visible to LAN subnet
Post by: RamSense on May 30, 2021, 12:44:31 pm
Hi community,

I have OpenVPN (ovpns2) running on Opnsense with IPv4 Tunnel Network 10.8.0.0/24, using Redirect Gateway and DNS Servers 192.168.1.1 (OpnSense)

My LAN (igb1) subnet 192.168.1.0 and subnetmask 255.255.255.0

VPN is running, I can see the LAN devices and other network items only available on local Lan.
I am using and running Roon Core/server on my Synology NAS. When I am outside and connected to VPN on my Opnsense I can start Roon on my iPhone and I can also see my local LAN endpoints to play music to. Only problem is that I can not see my iPhone as endpoint while on vpn. When I am at home on wifi, I can see my iPhone as endpoint in Roon.

I think it has to do with ROON detecting endpoints on the same subnet as LAN. How can I connect my VPN to the same subnet, or make my vpn connections visible to ROON LAN/subnet 192.168.1.0 / 255.255.255.0 ?

thank you very much for your help in advance!
Title: Re: OpenVPN connect/visible to LAN subnet
Post by: bartjsmit on May 30, 2021, 02:46:59 pm
There is an old thread about Roon's firewall restrictions: https://community.roonlabs.com/t/which-firewall-ports-destinations-does-roon-need-open-to-function/88309

If the assertion made there is true (Roon will only work on a flat network) then you may have to change your VPN from TUN to TAP with all the complications that will bring  :-\

Bart...
Title: Re: OpenVPN connect/visible to LAN subnet
Post by: RamSense on May 30, 2021, 08:02:34 pm
thanks for your help and pointing me to the Roon thread... I will take a look over there to find some more info....
hope I get it to work in some way.
Title: Re: OpenVPN connect/visible to LAN subnet
Post by: RamSense on May 31, 2021, 07:23:33 pm
I have read over there someone setting up ZeroTier VPN and got it working.
So I will be looking for a good Opnsense - ZeroTier Brigdge guide and try that out. Sounds better than a openvpn TAP mode (?)