Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

OpenVPN connects to gateway but unable to access local resources suchs as window shares or ping other computers

Posted on 2008-10-20
4
Medium Priority
?
1,529 Views
Last Modified: 2010-04-21
Hello,

   I am in need of some help, I have Endian firell setup and openVPN enabled. I am able to connect remotely to the openVPN server, I can ping the internal address of the endian firewall but unable to ping local LAN clients such as window servers that are located on the same network as the Endian firewall.  I am lost as I am able to even communicate with Endian firewall through my web browser using HTTP so I know I am accessing the local side of the openVPN connection yet all other resources are not accessable.

My client configuration file is


client
float
dev tap
proto tcp
port 80
remote nova.reddingtech.com
resolv-retry infinite
nobind
persist-key
persist-tun
ca Private_Network.cer
auth-user-pass
pull
comp-lzo


My remote client subnet is 192.168.1.0/24
my openVPN local subnet is 192.168.60.0/24

Please help!

Mon Oct 20 13:35:42 2008 OpenVPN 2.1_rc13 i686-pc-mingw32 [SSL] [LZO2] [PKCS11] built on Oct  7 2008
Mon Oct 20 13:35:47 2008 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
Mon Oct 20 13:35:47 2008 LZO compression initialized
Mon Oct 20 13:35:47 2008 Attempting to establish TCP connection with 75.60.56.210:80
Mon Oct 20 13:35:47 2008 TCP connection established with 75.60.56.210:80
Mon Oct 20 13:35:47 2008 TCPv4_CLIENT link local: [undef]
Mon Oct 20 13:35:47 2008 TCPv4_CLIENT link remote: 75.60.56.210:80
Mon Oct 20 13:35:47 2008 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Mon Oct 20 13:35:48 2008 [127.0.0.1] Peer Connection Initiated with 75.60.56.210:80
Mon Oct 20 13:35:50 2008 TAP-WIN32 device [Local Area Connection] opened: \\.\Global\{0C6269DF-7766-4A8A-AF85-F8047733B060}.tap
Mon Oct 20 13:35:50 2008 Notified TAP-Win32 driver to set a DHCP IP/netmask of 192.168.60.129/255.255.255.0 on interface {0C6269DF-7766-4A8A-AF85-F8047733B060} [DHCP-serv: 192.168.60.0, lease-time: 31536000]
Mon Oct 20 13:35:50 2008 Successful ARP Flush on interface [25] {0C6269DF-7766-4A8A-AF85-F8047733B060}
Mon Oct 20 13:35:55 2008 Initialization Sequence Completed

Open in new window

0
Comment
Question by:bcamacho
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 5

Expert Comment

by:dcsdave
ID: 22762045
Sounds like a DNS issue.  Have you tried accessing the information by IP as well as name?
0
 
LVL 2

Accepted Solution

by:
m_adamczyk earned 2000 total points
ID: 22801965
Your issue will not be in the remote config file. It might be in the OpenVPN server config file, but more likely it is a firewall configuration issue.

Haven't used Endian before, but if it supports IPTABLES commands, I've found the following command to be key in many of my configurations:
iptables -I FORWARD -i tap+ -j ACCEPT

You already have incoming tap connections allowed (iptables -I INPUT -i tap+ -j ACCEPT) but you're not getting past the firewall device which is why I think it's a firewall configuration issue. If Endian doesn't look at the interface time, try opening access for the OpenVPN subnet (192.168.60.0) to the LAN subnet.

Good luck.
0
 
LVL 2

Expert Comment

by:m_adamczyk
ID: 22804181
CORRECTION: I meant
...If Endian doesn't look at the interface TYPE, try opening access for the OpenVPN subnet...
0
 
LVL 1

Author Closing Comment

by:bcamacho
ID: 31508009
Problem solved
0

Featured Post

Building an interactive eFuture classroom

Watch and learn how ATEN provided a total control system solution including seamless switching matrix switch, HDBaseT extenders, PDU, lighting control to build an interactive eFuture classroom.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Configuring network clients can be a chore, especially if there are a large number of them or a lot of itinerant users.  DHCP dynamically manages this process, much to the relief of users and administrators alike!
If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question