LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 08-20-2015, 06:58 AM   #1
robertkwild
Member
 
Registered: Feb 2015
Posts: 382

Rep: Reputation: Disabled
openVPN - got it working on 2nd firewall


hi all,

my problem was when i set up an openvpn server on my pfsense fw, as the pfsense fw is the 2nd public fw, our main public fw is TMG, our main TMG fw we have set static routes to and from our main VLAN switch, so when our VPN clients connect to pfsense fw they couldnt access any remote networks apart from the LAN that pfsense fw is on, even when i set up the static routes for each VLAN on the pfsense fw and added the other remote subnets on the openvpn server

the solution was to create a static route on my main VLAN switch for my virtual VPN network and the gateway was set to the openvpn server ie pfsense fw and now my VPN clients can connect to remote networks not just the LAN that the pfsense was on

rob
 
Old 08-20-2015, 07:41 AM   #2
paul2015
Member
 
Registered: Apr 2015
Distribution: CentOS Fedora
Posts: 149

Rep: Reputation: 4
I would never intall TMG if I have pfsense on my network.
 
Old 08-20-2015, 07:56 AM   #3
robertkwild
Member
 
Registered: Feb 2015
Posts: 382

Original Poster
Rep: Reputation: Disabled
same here mate but TMG was installed before pfsense was, i just installed pfsense as our back door in, incase TMG goes down, i would never trust a fw on windows!
 
Old 08-20-2015, 07:59 AM   #4
paul2015
Member
 
Registered: Apr 2015
Distribution: CentOS Fedora
Posts: 149

Rep: Reputation: 4
have you ever configured pfsense with load balancer and failover and squid and squidguard proxy server? load balancer is working failover is working but proxy has problem with second wan. other traffic is running just proxy has problem when first wan is down.
 
Old 08-20-2015, 08:05 AM   #5
robertkwild
Member
 
Registered: Feb 2015
Posts: 382

Original Poster
Rep: Reputation: Disabled
no i have not as i dont have two public ip addreses (one public ip for pfsense a and one public ip for pfsense b)

and also you need to create a new vlan for it aswell on your switch so the 2 can communicate (or just have one spare nic on both pfsense machines so the 2 can talk)

have you checked this out

https://doc.pfsense.org/index.php/Co...dundancy_(CARP)

Last edited by robertkwild; 08-20-2015 at 08:09 AM.
 
Old 08-20-2015, 08:10 AM   #6
paul2015
Member
 
Registered: Apr 2015
Distribution: CentOS Fedora
Posts: 149

Rep: Reputation: 4
yes but i am using only one powerful machine with 4 NIC cards. 2 wan 1 lan and 1 captive portal. So failover works but only proxy does not work. I thing I have to dig more backup is good idea.
 
Old 08-20-2015, 08:11 AM   #7
robertkwild
Member
 
Registered: Feb 2015
Posts: 382

Original Poster
Rep: Reputation: Disabled
sorry paul havnt done it otherwise i would help, ask pfsense forum, there really helpfull
 
Old 08-20-2015, 08:16 AM   #8
paul2015
Member
 
Registered: Apr 2015
Distribution: CentOS Fedora
Posts: 149

Rep: Reputation: 4
it's ok thanks
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how can i make openvpn working without nating in firewall saravanakumar Linux - Server 2 07-26-2011 03:39 PM
Cannot connect to 2nd openvpn qwertyjjj Linux - Server 0 08-04-2010 07:18 AM
2nd tun network for openvpn? qwertyjjj Linux - Server 1 08-03-2010 08:48 AM
2nd openvpn no response qwertyjjj Linux - Newbie 5 08-02-2010 12:49 PM
Server with two IP addresses, how do I use the 2nd one for an openvpn tunnel? remote42 Linux - Networking 0 06-21-2009 02:15 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 08:22 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration