OpenVPN mobile client establishes connection but cannot see or be seen by LAN devices

OpenVPN mobile client establishes connection but cannot see or be seen by LAN devices

OpenVPN mobile client establishes connection but cannot see or be seen by LAN devices
OpenVPN mobile client establishes connection but cannot see or be seen by LAN devices
2025-05-24 14:13:35 - last edited 2025-06-19 01:24:44
Model: Archer C5400X  
Hardware Version: V1
Firmware Version: 1.1.7 Build 20240510 rel.17306(4555)

Information

DDNS is set up and working.

I'm able use the router-generated OVPN config to connect both an Android and Linux device to the router VPN server.

The router VPN configuration is set to Home and Internet, and I can access the internet via both VPN clients.

The VPN client devices can ping the router on 192.168.0.1

The VPN clients cannot ping a server on the LAN at 192.168.0.100

The LAN server cannot see the VPN clients on their internal 10.8.0.6 and 10.8.0.10 IPs.

 

Routes explored

1. Setting the OpenVPN IP assignment and LAN DHCP assignment to be adjacent in 192.168.0.0/24

e.g. OpenVPN 192.168.0.200-240, LAN DHCP 192.168.0.50-199

2. Adjusting TCP and UDP mode

3. Using static routing to put 10.8.0.0/24 to 192.168.0.1

 

So far I've had no success. Any help would be greatly appreciated!

 

 

  0      
  0      
#1
Options
1 Accepted Solution
Re:OpenVPN mobile client establishes connection but cannot see or be seen by LAN devices-Solution
2025-05-24 15:54:22 - last edited 2025-06-19 01:24:44

  @dfiuyb123876daf 

 

dfiuyb123876daf wrote

 

The VPN clients cannot ping a server on the LAN at 192.168.0.100

 

 

Hi,

 

This can be due to firewall settings of the local devices on the VPN server's network. The devices on the VPN server's local network treat a connection coming from a VPN client as a "remote" connection. By default, firewalls usually block most communications coming from a remote device.

For a test you could temporarily turn off the whole firewall of the server on the LAN and see if that allows the VPN client to ping it at 192.168.0.100.

 

dfiuyb123876daf wrote

 

The LAN server cannot see the VPN clients on their internal 10.8.0.6 and 10.8.0.10 IPs.

  

 

This appears to be intentional.

If you require Site-to-Site VPN capabilities, then TP-Link offers their "Omada" range of products for that.

 

Recommended Solution
  0  
  0  
#2
Options
1 Reply
Re:OpenVPN mobile client establishes connection but cannot see or be seen by LAN devices-Solution
2025-05-24 15:54:22 - last edited 2025-06-19 01:24:44

  @dfiuyb123876daf 

 

dfiuyb123876daf wrote

 

The VPN clients cannot ping a server on the LAN at 192.168.0.100

 

 

Hi,

 

This can be due to firewall settings of the local devices on the VPN server's network. The devices on the VPN server's local network treat a connection coming from a VPN client as a "remote" connection. By default, firewalls usually block most communications coming from a remote device.

For a test you could temporarily turn off the whole firewall of the server on the LAN and see if that allows the VPN client to ping it at 192.168.0.100.

 

dfiuyb123876daf wrote

 

The LAN server cannot see the VPN clients on their internal 10.8.0.6 and 10.8.0.10 IPs.

  

 

This appears to be intentional.

If you require Site-to-Site VPN capabilities, then TP-Link offers their "Omada" range of products for that.

 

Recommended Solution
  0  
  0  
#2
Options