OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 21.1 Legacy Series »
  • OpenVPN access clients from LAN
« previous next »
  • Print
Pages: [1]

Author Topic: OpenVPN access clients from LAN  (Read 1810 times)

jbaileypro

  • Newbie
  • *
  • Posts: 3
  • Karma: 1
    • View Profile
OpenVPN access clients from LAN
« on: February 24, 2021, 04:09:10 pm »
Hi all,

I've used the OpenVPN wizard to setup the VPN successfully (including using AD for authentication). One of the OpenVPN clients is a Synology NAS which is used for a offsite backup location. The backup source is a server on the LAN.

OpenVPN clients can connect and communicate with LAN devices but not the other way around.

I've tried static routes but it doesn't allow creation without a parent interface which I've tried creating but doesn't seem to work.

Does anyone have any ideas?

Layout is:
LAN: 10.0.0.0/8
OpenVPN: 172.16.10.0/24

NAS for example gets 172.16.10.200/24
Server for example is: 10.0.10.50/8

NAS can ping and browse shares on 10.0.10.50 server. Server cannot ping or access 172.16.10.200 Synology.

Thanks all,


Logged

lfirewall1243

  • Hero Member
  • *****
  • Posts: 1386
  • Karma: 45
    • View Profile
Re: OpenVPN access clients from LAN
« Reply #1 on: February 24, 2021, 08:49:24 pm »
Quote from: jbaileypro on February 24, 2021, 04:09:10 pm
Hi all,

I've used the OpenVPN wizard to setup the VPN successfully (including using AD for authentication). One of the OpenVPN clients is a Synology NAS which is used for a offsite backup location. The backup source is a server on the LAN.

OpenVPN clients can connect and communicate with LAN devices but not the other way around.

I've tried static routes but it doesn't allow creation without a parent interface which I've tried creating but doesn't seem to work.

Does anyone have any ideas?

Layout is:
LAN: 10.0.0.0/8
OpenVPN: 172.16.10.0/24

NAS for example gets 172.16.10.200/24
Server for example is: 10.0.10.50/8

NAS can ping and browse shares on 10.0.10.50 server. Server cannot ping or access 172.16.10.200 Synology.

Thanks all,
Set up a S2S connection which is made for that
Logged
(Unoffial Community) OPNsense Telegram Group: https://t.me/joinchat/0o9JuLUXRFpiNmJk

PM for paid support

jbaileypro

  • Newbie
  • *
  • Posts: 3
  • Karma: 1
    • View Profile
Re: OpenVPN access clients from LAN
« Reply #2 on: February 24, 2021, 10:41:27 pm »
Worked out the issue.

The gateway for the default firewall rule was set to a failover group on the LAN side. As this wasn't the default routing table it wasn't able to route to the VPN.

To fix this I added a new firewall, from = LAN network, to = VPN network, gateway = default and voila. LAN was now able to speak to VPN clients now too!

Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 21.1 Legacy Series »
  • OpenVPN access clients from LAN
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2