OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • [SOLVED] IPsec Road Warrior: No Internet only access to LAN
« previous next »
  • Print
Pages: [1]

Author Topic: [SOLVED] IPsec Road Warrior: No Internet only access to LAN  (Read 2768 times)

Dobi

  • Newbie
  • *
  • Posts: 9
  • Karma: 1
    • View Profile
[SOLVED] IPsec Road Warrior: No Internet only access to LAN
« on: September 10, 2021, 08:01:56 pm »
Hello,

I read the following guides:
https://docs.opnsense.org/manual/how-tos/ipsec-road.html
https://docs.opnsense.org/manual/how-tos/ipsec-rw-srv-eapradius.html
https://docs.opnsense.org/manual/how-tos/ipsec-rw-android.html#ikev2-eap-mschapv2-or-eap-radius

I also read the following topics on the same problem I have:
https://forum.opnsense.org/index.php?topic=11340.0
https://forum.opnsense.org/index.php?topic=19404.0
https://github.com/opnsense/core/issues/3751


Accessing the LAN I have no problems, but I don't get my IPsec clients to access the internet over VPN.

Greetings,
Dobi
« Last Edit: September 16, 2021, 05:00:34 pm by Dobi »
Logged

Dobi

  • Newbie
  • *
  • Posts: 9
  • Karma: 1
    • View Profile
Re: IPsec Road Warrior: No Internet only access to LAN
« Reply #1 on: September 10, 2021, 08:02:40 pm »
Here are the IPsec settings.
« Last Edit: September 10, 2021, 08:57:20 pm by Dobi »
Logged

Dobi

  • Newbie
  • *
  • Posts: 9
  • Karma: 1
    • View Profile
Re: IPsec Road Warrior: No Internet only access to LAN
« Reply #2 on: September 10, 2021, 08:03:27 pm »
Here are some status information.
Logged

Dobi

  • Newbie
  • *
  • Posts: 9
  • Karma: 1
    • View Profile
Re: IPsec Road Warrior: No Internet only access to LAN
« Reply #3 on: September 16, 2021, 05:00:00 pm »
I found the solution. See attached file.

No need for NAT, no need for Reflection as described in some topics.
Logged

danny.su

  • Newbie
  • *
  • Posts: 1
  • Karma: 0
    • View Profile
Re: [SOLVED] IPsec Road Warrior: No Internet only access to LAN
« Reply #4 on: November 15, 2021, 04:28:09 pm »
 :'( I just follow your setting, but it not work. Could you give me some notice?
My setting info:
1.firewall -> ipsec->ipv4 * * * * *
2.firewall -> wan->IPV4 ESP * * WAN ADDRESS * * (then 500,4500)
3.firewall -> NAT->hybrid->wan ipv4 10.10.8.0/24 * * * WAN ADDRESS
4.ipsec->mobile client -> virtual address pool->10.10.8.0/24
5.ipsec->mobile client -> DNS SERVER->8.8.8.8
6.ipsec->tunnel settings->proposal 1 follow wiki
7.ipsec->tunnel settings->proposal 1 follow wiki (local network follow you 0.0.0.0/0)
Now it no access internet only lan , I have no idea how to fix it, Could you give me some advice?
« Last Edit: November 15, 2021, 04:36:04 pm by danny.su »
Logged

djbobyd

  • Newbie
  • *
  • Posts: 1
  • Karma: 0
    • View Profile
Re: [SOLVED] IPsec Road Warrior: No Internet only access to LAN
« Reply #5 on: May 04, 2022, 03:04:23 pm »
Quote from: Dobi on September 16, 2021, 05:00:00 pm
I found the solution. See attached file.

No need for NAT, no need for Reflection as described in some topics.
Thanks a lot for the solution, Dobi. I've spent several hours already looking for it.
One additional step to anyone who will also try this solution. In the Firewall Rules section for the IPsec you should add an inbound rule any-to-any in order for the traffic to be allowed back. After I did this, together with the proposed solution by Dobi everything worked like a charm.
Once again, thanks a lot, Dobi!!!
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • [SOLVED] IPsec Road Warrior: No Internet only access to LAN
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2