Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
19.7 Legacy Series
»
New OpenVPN server setup - can connect but can't talk to internal IPs
« previous
next »
Print
Pages: [
1
]
Author
Topic: New OpenVPN server setup - can connect but can't talk to internal IPs (Read 2179 times)
cmay
Newbie
Posts: 12
Karma: 0
New OpenVPN server setup - can connect but can't talk to internal IPs
«
on:
September 27, 2019, 10:24:37 pm »
Hi, I followed the tutorial for OpenVPN road warrior server setup with 2FA. I am able to connect to the VPN and get a VPN client IP, but I cannot talk to internal IPs. I have set up the firewall rules to allow VPN traffic and to allow communication from the VPN clients (at 10.10.10.0/24) to my LAN (192.168.0.0/24) per the screenshot below, but no luck.
Any help would be appreciated. Thanks.
Logged
banym
Sr. Member
Posts: 468
Karma: 31
Free Human Being, FreeBSD, Linux and Mac nerd
Re: New OpenVPN server setup - can connect but can't talk to internal IPs
«
Reply #1 on:
September 27, 2019, 11:22:11 pm »
Hi cmay,
that second rule is located on the wrong interface.Looks like you have the rule on WAN interface. It should be under OpenVPN than it should work as expected.
Logged
Twitter: banym
Mastodon: banym@bsd.network
Blog:
https://www.banym.de
cmay
Newbie
Posts: 12
Karma: 0
Re: New OpenVPN server setup - can connect but can't talk to internal IPs
«
Reply #2 on:
September 28, 2019, 12:49:48 am »
Thanks. I did have it under WAN instead of OpenVPN. I fixed that, but still have the issue.
Logged
banym
Sr. Member
Posts: 468
Karma: 31
Free Human Being, FreeBSD, Linux and Mac nerd
Re: New OpenVPN server setup - can connect but can't talk to internal IPs
«
Reply #3 on:
September 28, 2019, 10:50:26 pm »
Make a package capture on the OpenVPN interface and on the internal LAN interface to check if the packages are passed correctly.
You should see the answers from the clients if you ping from VPN.
If you need more help please post the screenshots of your configuration: LAN, WAN, OpenVPN configuration and the details what network addresses you are using.
If the connection is established it is a routing or a firewall rule problem in the most cases.
Logged
Twitter: banym
Mastodon: banym@bsd.network
Blog:
https://www.banym.de
cmay
Newbie
Posts: 12
Karma: 0
Re: New OpenVPN server setup - can connect but can't talk to internal IPs
«
Reply #4 on:
September 29, 2019, 06:18:09 am »
Got it to work. It must have been that first fix of the WAN rule that needed to go to an OpenVPN rule. When I tested it after that fix I didn't think it was working because I was trying to ping a device that I had recently changed its IP on, doh. Thanks for the help!
I am still having one issue in that my public IP is not changing, still showing as the nonvpn public IP. Will start another thread for that. Thanks again.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
19.7 Legacy Series
»
New OpenVPN server setup - can connect but can't talk to internal IPs