I have an OpenVPN roadwarrior configured in bridged mode. OpenVPN client connects successfully.
The problem is that I’m able to access only the gateway/nethserver. Other servers from the LAN are not accessible.
I found this in the logs, but I can’t tell if is related to the problem or not:
Jun 3 19:29:53 router kernel: Shorewall:loc2fw:REJECT:IN=br0 OUT= MAC=00:0c:29:ed:2f:cb:00:ff:3d:82:ae:96:08:00 SRC=192.168.2.201 DST=192.168.2.254 LEN=96 TOS=0x00 PREC=0x00 TTL=128 ID=23368 PROTO=UDP SPT=137 DPT=137 LEN=76
192.168.2.201 is the VPN client IP.
192.168.2.254 is the gateway IP.
I have in identical setup at different place and there OpenVPN roadwarrior is working fine without any problems.
I tried from two networks with different subnets, both different from the LAN subnet and it doesn’t work.
At this point I don’t even know where to look for the problem. Which logs should I check.
The client OS is Windows 10 Pro.
I tried to ping from both sides. The ping works only between the client and the gateway on both directions.
Nothing else is accessible from the LAN.
I tried to disable the firewall at both ends but no change. I can’t tell if is a firewall issue or else.
Just to be clear and that I understand you correctly:
if you open a ssh session from a LAN-machine to this NS you can ping other machines and
if you open a ssh session from a vpn-machine to this NS you can not ping other machines??
I don’t think this is possible at all.
Are you sure you green interface (br0) is up and working and your tap-interface and ens192 are joined to br0? Please control with:
The red interface is WAN the green is LAN. I can ping anything from the gateway from LAN and from WAN.
There is no restriction in the LAN, everybody can ping anybody except the machine connected with VPN client.
From the VPN client I can ping only the Nethserver gateway(green interface) from the LAN.
If routed mode satisfy your needs, I’d go with routed mode, also it is the recommended way.
Every thing seems o.k. on your machine. All interfaces are up, ens192 and tap0 are joined to br0.
ATM can’t see anything wrong.
Good luck.