In the client peer definition, it's 0.0.0.0/0. On the OPNSense side, it's 192.168.5.2/32.
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuQuote from: viragomann on October 03, 2025, 01:09:34 PMOK, here goes. It's the first time I respond to that type of request so if there is a different way I should share the settings, please let me know.Quote from: beneix on October 02, 2025, 09:54:06 PMOK, what I am missing is the part of how to set up the VLAN so that all traffic from it routes via the VPN.
All necessary steps are explained above.
If you have trouble anyway, show all details of your settings, please.












Quote from: cookiemonster on October 02, 2025, 11:10:23 PMBut do you have a managed switch to tag the traffic of this VLAN, and have setup your interface in OPN to act as the trunk from it?Yes, I have a managed switch for the Ethernet connection, but I also have my Unifi AP that will broadcast a separate SSID for the VLAN (I am doing this already for another VLAN). The WiFi connection will be the main way this VPN VLAN will be used, the Ethernet is just a back-up.
If not, you don't have a VLAN but perhaps a separate network on a separate interface in OPN? I'm a bit unclear.
Quote from: viragomann on October 02, 2025, 06:21:03 PMRight, but what local IP address does a client connecting to the VLAN get? In order for the NAT rule to translate source addresses, there need to be source addresses to translate...I must be missing something?Quote from: beneix on October 02, 2025, 06:13:29 PMI see in the interfaces overview that the new interface has IPv4 and routes set to 10.100.0.2/16. Is this the range of addresses that will be handed out to clients connecting to the VLAN?This is your VPN client IP.
It's not range, but just a single IP and you cannot hand it out to any other device.
If you route traffic to the VPN server, the suggested outbound NAT rule translates the source address into this one, so that responses are coming back to you.
There is nothing to configure in the VPN interface settings. Just enable it.
IP address assignment is done by the VPN server.
Quote from: tessus on July 29, 2025, 07:47:34 AM@beneix may I ask when you installed your system?The system was purchased in 2022 and I installed UFS. Then in 2024 I decided to take the leap and re-install with ZFS - I think it was when 24.7.1 was out. I don't recall giving any particular input to sizing, I think I just let the installer set the defaults, but I could be wrong.