Network Resource Access Across Subnets


Recommended Posts

Just to check in pfSense under Services > VPN > Servers > *Your VPN Server* find the section called "IPv4 Local network(s)" make sure your normal network subnet is there. I'm not sure what the CIDR notation is for your particular setup. Also, make sure to provide the normal DNS server to the VPN client, typically it will be the Local Network's DNS server (that interface's IP).

 

Hello there.

 

There is no; Services > VPN > Servers > *Your VPN Server*, I am presuming you mean; VPN > OpenVPN > Servers > *Your VPN Server*. If so there is also no section called "IPv4 Local network(s)".

 

My LAN DNS server is listed correctly.

 

What version of pfSense are you on? I pulled that from my 2.3.2 box, and correct about the Services bit... The "IPv4 Local Network(s)" is under "Tunnel Settings"

 

Version 2.3.2-Release-p1

 

There is no 'VPN' menu under services. See picture.

 

People on PFSense forums are telling me that since I can get a VPN connection and can ping local IP addresses that PFSense is working correctly. They are saying that not being able to access my shares is a problem with unRaid.

 

pfsense.jpg.47818ecad222fa11cf4f9c6a097a14d2.jpg

Link to comment

Just to check in pfSense under Services > VPN > Servers > *Your VPN Server* find the section called "IPv4 Local network(s)" make sure your normal network subnet is there. I'm not sure what the CIDR notation is for your particular setup. Also, make sure to provide the normal DNS server to the VPN client, typically it will be the Local Network's DNS server (that interface's IP).

 

Hello there.

 

There is no; Services > VPN > Servers > *Your VPN Server*, I am presuming you mean; VPN > OpenVPN > Servers > *Your VPN Server*. If so there is also no section called "IPv4 Local network(s)".

 

My LAN DNS server is listed correctly.

 

What version of pfSense are you on? I pulled that from my 2.3.2 box, and correct about the Services bit... The "IPv4 Local Network(s)" is under "Tunnel Settings"

 

Version 2.3.2-Release-p1

 

There is no 'VPN' menu under services. See picture.

 

People on PFSense forums are telling me that since I can get a VPN connection and can ping local IP addresses that PFSense is working correctly. They are saying that not being able to access my shares is a problem with unRaid.

 

Go to VPN > Openvpn > edit your setup and go down until you find tunnel settings and look for IPv4 Local network(s).

If you tell us your IP range and subnet mask we can tell you if it's correct or not. Also supply what is set there now.

Link to comment

I am presuming there is a setting somewhere on unRaid that is blocking access to the shares from a VPN connection.

 

I don't think that is the case.

 

I maintain two unRAID systems on two different networks, I'll call them "home" and "remote".  The home server is running unRAID 6.3.0 rc1 and the remote one is on unRAID 6.2.1.  There is a router-based (Asus Merlin OpenVPN) site-to-site VPN connection between the home and remote locations.  I am able to access SMB shares on the remote server from Win 10 machines on my home network without any problems.

 

To test your use case, I went to Starbucks this morning and vpn'd to the remote router directly from my Win 10 laptop, and was still able to access SMB shares on the remote unRAID system.

 

So I'm not sure why it isn't working for you, but I really don't think unRAID is doing anything to block your VPN / other subnet connections.

 

 

A couple of other points:

  • I have had problems with name resolution in the past, so I manually added both unRAID systems to my Windows hosts and lmhosts files (in c:\windows\system32\drivers\etc) and that solved the problem.
  • My work laptop is part of a domain for work, and not my local workgroup.  This complicates authentication, but can be solved by going to the Windows Credential Manager and adding a "Windows Credential" for each unRAID server.

Hope it helps!

 

Using unRaid to run WINS I could access shares and I had name resolution -- the issue is just browsing.

 

Browsing isn't a big issue but since I have it working using the other computers I might as well keep it that way

Link to comment

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.