Netgate SG-1000 microFirewall

Author Topic: Unable to connect to vpn server if vpn client is runing  (Read 211 times)

0 Members and 1 Guest are viewing this topic.

Offline mdahal

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
Unable to connect to vpn server if vpn client is runing
« on: January 14, 2018, 07:45:33 am »
Good evening,

I have successfully set up one vpn server to use as road wariror and 2 clients for selective routing using PIA.

However, every time I try to connect to the server when clients are running the connection is stuck at waiting for server and get  TLS key negotiation failed to occur within 60 seconds (check your network connectivity) in pfsense openvpn log.

If I stop both clients I am able to connect again to server. My clients are connected fine and can route to it.
LAN - 192.168.2.0/24
OpenVPN Server : 10.0.0.0/24
Clinet 1 connected: 10.16.*.*
Client 2 connected: 10.20.*.*

I have checked everywhere but unable to fix the issue.

The only area I am not certain is outbound NAT. do I have to add any rule to allow VPN Connection.

Appreciate your help.
 




Offline viragomann

  • Hero Member
  • *****
  • Posts: 2828
  • Karma: +311/-1
    • View Profile
Re: Unable to connect to vpn server if vpn client is runing
« Reply #1 on: January 14, 2018, 04:57:57 pm »
Presumably you get the default route pushed by the PIA server. So responses to VPN connection requests are sent out to the PIA gateway.

You have to assign an interface to each VPN instance. Based on your outbound NAT rule, I guess you haven't done this yet.

To avoid that, go to the client setting and check "Don't pull routes".
Since you want set up selective routing to the PIA gateway, you have to set policy routing rules for directing traffic to PIA using the gateway you've assigned to the vpn instances.

Your outbound NAT rules are very strange. What is 10.10.10.1?
Have you defined a gateway on the WIFI interface? If yes, why?
What is IPMI? Have you defined a gateway on this interface? Why?

OpenVPN is an interface group containing all OpenVPN instances. You should define rules for each particular PIA VPN interface.

Offline mdahal

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
Re: Unable to connect to vpn server if vpn client is runing
« Reply #2 on: January 15, 2018, 08:58:27 pm »
Thank you Viragomann,

Really appreciate your help.

I have added  route for one which made both work. Its the vpn to one. I have also created interface for each vpn instance.

I will try using "Don't pull routes" and report tonight.

Furthermore,
10.10.10.1 was another vpn server I had which is deleted now.
IPMI and WIFI are two interfaces that are't connected at ghe moment but I am planning to run wifi and all my devices management through them.

Cheers

Offline Derelict

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 10260
  • Karma: +1177/-313
    • View Profile
Re: Unable to connect to vpn server if vpn client is runing
« Reply #3 on: January 15, 2018, 09:21:45 pm »
Quote
Presumably you get the default route pushed by the PIA server. So responses to VPN connection requests are sent out to the PIA gateway.

That is not actually true. Unless the functionality has been disabled (or something silly like using an interface group for WAN rules), connections coming into a WAN interface get marked with reply-to forcing reply traffic back out the same interface on which it arrived regardless of the contents of the routing table.

I have not quite wrapped my head around why multiple OpenVPN connections give people so much trouble.

Outbound NAT means nothing when connecting TO an OpenVPN server. Bad OB NAT might prevent you from being able to access the internet through that server after you have connected, but it will not impact the connection at all.

You are testing the OpenVPN server from the outside right?
« Last Edit: January 16, 2018, 10:29:02 am by Derelict »
Las Vegas, Nevada, USA
Use this diagram to describe your issue.
The pfSense Book is now available for just $24.70!
Do Not PM For Help! NO_WAN_EGRESSTM

Offline viragomann

  • Hero Member
  • *****
  • Posts: 2828
  • Karma: +311/-1
    • View Profile
Re: Unable to connect to vpn server if vpn client is runing
« Reply #4 on: January 16, 2018, 07:31:45 am »
Yes, I know the reply-to function of pfSense, but in a manner of speaking I'm in doubt, that it works well in any set up. Often it seems that response packets are replied to the default gateway though.

Offline Derelict

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 10260
  • Karma: +1177/-313
    • View Profile
Re: Unable to connect to vpn server if vpn client is runing
« Reply #5 on: January 16, 2018, 10:30:28 am »
It works every time. If it does not, it means that some other condition is present that is preventing reply-to from being added to the state.
Las Vegas, Nevada, USA
Use this diagram to describe your issue.
The pfSense Book is now available for just $24.70!
Do Not PM For Help! NO_WAN_EGRESSTM

Offline mdahal

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
Re: Unable to connect to vpn server if vpn client is runing
« Reply #6 on: January 17, 2018, 06:21:44 am »
Hi Derelict and viragomann,

Thank you for your responses. Yes I am testing from outside.

Just tried using do not pull routes. Disabled interfaces and re-enabled interface and it seems to be working now.

Really appreciate your help!!

Regards,
mdahal
« Last Edit: January 17, 2018, 07:26:16 am by mdahal »