Possibly stupid question but I didn't see you explicitly state it:
Can the WiFi devices talk to each other and can wired devices on the
Internal Lan talk to the WiFi devices?
----- Message from Shorewall via Shorewall-users
<shorewall-users@lists.sourceforge.net> ---------
Date: Mon, 06 Jul 2020 09:35:46 -0700
From: Shorewall via Shorewall-users
<shorewall-users@lists.sourceforge.net>
Reply-To: shorew...@gemneye.org, Shorewall Users
<shorewall-users@lists.sourceforge.net>
Subject: [Shorewall-users] Shorewall / OpenVpn / Mesh Wifi
To: Shorewall-users@lists.sourceforge.net
Cc: Shorewall <shorew...@gemneye.org>
I have an issue, which I don't believe is Shorewall related, but as
I have posted similar message to OpenVPN forums I thought I would
try here in case I am missing something.
So I have a pretty typical OpenVPN setup where remote "road-warrior"
clients can connect to OpenVPN server (the same server as
shorewall). The VPN network is a routed network in that remote VPN
clients are own their own network. The remote VPN clients can route
through to the internet, can talk to the VPN server, and can also
communicate with devices on the "internal LAN" network if the device
is directly connected (via ethernet) to the Shorewall server.
Here is the problem. I also have a mesh wifi network which I have
bridged to the "internal LAN" network. All the devices on the
"internal LAN" can communicate with one another as expected. What
does not work is remote VPN clients being able to communicate to
devices that are connected to the "internal LAN" via the wifi mesh
network. So although everything works as expected on the "internal
LAN", and remote VPN client can communicate with "internal LAN"
devices that are directly connected, a remote vpn client cannot
connect to devices on the same network if they are connected via
wifi mesh.
Since Shorewall routes and allows communication to the "internal
LAN", the expectation was that it would work with the wifi connected
devices. So I don't know if this is a OpenVPN thing, a Shorewall
thing, or just a limitation of how I have chosen to implement my
network.
I saw a post on SuperUser (a few years old) where someone was
reporting a similar issue, but there was not an answer.
With all the smart people here, I thought I would ask here and see
if this is an issue related to firewall/routing.
Thank You.
_______________________________________________
Shorewall-users mailing list
Shorewall-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/shorewall-users
----- End message from Shorewall via Shorewall-users
<shorewall-users@lists.sourceforge.net> -----
--
Mark D Montgomery II
techi...@techiem2.net
https://www.techiem2.net
_______________________________________________
Shorewall-users mailing list
Shorewall-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/shorewall-users