This points to missing routes from VPN to your LAN? At System: Routes...
That's my thinking as well. When I connect to the VPN, I cannot reach the firewall until I manually add a route on my Mac:
sudo route -n add 172.16.7.1/24 172.16.72.48
Topology:
Firewall - 172.16.7.1 (/24)
VPN range - 172.16.72.48 (/28, with .47 being the firewall)
How does one set up a route to be pushed to VPN clients correctly? The only gateway options I have under System > Routes are:
- WAN_DHCP
- Null4
- Null6
I created a new gateway and route, but no traffic goes through it. Does anyone have a working VPN setup (PPTP or OpenVPN) that passes traffic through to LAN net?
Got a bit further into my research and found that the firewall's OpenVPN address also can't ping the local net (using Interfaces > Diagnostics > Ping):
PING 172.16.7.105 (172.16.7.105) from 10.0.7.1: 56 data bytes
--- 172.16.7.105 ping statistics ---
3 packets transmitted, 0 packets received, 100.0% packet loss
Whereas it can from the LAN interface:
PING 172.16.7.105 (172.16.7.105) from 172.16.7.1: 56 data bytes
64 bytes from 172.16.7.105: icmp_seq=0 ttl=64 time=1.744 ms
64 bytes from 172.16.7.105: icmp_seq=1 ttl=64 time=0.818 ms
64 bytes from 172.16.7.105: icmp_seq=2 ttl=64 time=0.680 ms
--- 172.16.7.105 ping statistics ---
3 packets transmitted, 3 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 0.680/1.081/1.744/0.472 ms
As I suspected initially, it feels like the firewall can't route between the two subnets (VPN and LAN) correctly.