What's new

Phones Connected to VPN Server Can Only Ping LAN Clients

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

doodlenoodle

Occasional Visitor
  • AC86u Router - 384.13 Asuswrt-Merlin
  • OpenVPN Server - Enabled
  • VPN Client 1 TorGuard VPN - Enabled
  • Remote Client (Phone or PC) using OpenVPN

When using a PC outside of my network (using cellular hotspot to test) I can successfully VPN to my Merlin powered router via OpenVPN . LAN clients are then reachable. I can ping the internal LAN devices and I can access their administrative webpages. i.e. synology NAS interface, asus router login page, even NVIDIA shield using Vysor. All is well.
PC connecting to Merlin powered router is using openvpn2.4.7-I607-Win10

PROBLEM:
The same is NOT true when using a mobile phone to connect to the router via VPN (OpenVPN). I can successfully ping the LAN clients, but cannot access their administrative interfaces or webpage. Again this means i.e. Asuswrt-Merlin router login page (192.168.50.1), Synology DSM login page for NAS. However, if I disconnect from VPN and connect back to my Wi-Fi (same network as lan clients) then I can reach the LAN clients login pages again from the phone, the phone is able to reach the LAN client's administrative pages, just not when on VPN for some reason.

  • Safari or Chrome (on both phones) are the browsers used to try to reach pages
  • iPhone 7 OpenVPN 3.0.3 (2104)
  • Samsung S10 OpenVPN 3.0.7 (3565)
  • Imported same .ovpn file on PC and Phones
I've uploaded some screenshots
  • OpenVPN Server Advanced Settings Page --Thumbnail1
  • VPN Status Page (PC Connected) -- Thumbnail2
  • PC Connected via VPN (Can ping router IP and access Login Page) --Thumbnail3, 4
  • VPN Status Page (iPhone Connected) --Thumbnail5
  • iPhone OpenVPN App showing connected --Thumbnail6
  • iPhone Ping App (Can ping 2 devices in my LAN) --Thumbnail7, 8
  • iPhone trying to connect to Asus router login page (stuck loading) --Thumbnail9
  • iPhone disconnected from VPN and back on Wi-Fi local network (can connect to Router Login Page) --Thumbnail10
Any guidance that can be provided would be greatly appreciated.

Asus OpenVPN Server Screenshot 1.png Asus OpenVPN Server Screenshot 2.png Asus OpenVPN Status PC Connected Screenshot 3.png PC Connected to VPN Can Ping and Access LAN Resources Screenshot 3.png Asus OpenVPN Status iPhone Connected Screenshot 4.png
 
Last edited:
  • AC86u Router - 384.13 Asuswrt-Merlin
  • OpenVPN Server - Enabled
  • VPN Client 1 TorGuard VPN - Enabled
When using a PC outside of my network (using cellular hotspot to test) I can successfully connect to my Merlin powered router. LAN clients are reachable. I can ping the internal LAN devices and I can access their webpages. i.e. synology NAS interface, asus router login page, even NVIDIA shield using Vysor. All is well.
PC connecting to Merlin powered router is using openvpn2.4.7-I607-Win10

PROBLEM:
The same is NOT true when using mobile devices running OpenVPN. I can ping the LAN clients, but cannot access their interfaces or webpage. Again this means i.e. Asuswrt-Merlin router login page (192.168.50.1), Synology DSM login page for NAS. However, if I disconnect from VPN and connect back to my Wi-Fi (same network as lan clients) then I can reach the LAN clients login pages again from the phones proving that phones can access those pages.

  • Safari or Chrome (on both phones) are the browsers used to try to reach pages
  • iPhone 7 OpenVPN 3.0.3 (2104)
  • Samsung S10 OpenVPN 3.0.7 (3565)
  • Imported same .ovpn file on PC and Phones
I've uploaded some screenshots
  • OpenVPN Server Advanced Settings Page
  • VPN Status Page (PC Connected)
  • PC Connected via VPN (Can ping router IP and access Login Page)
  • VPN Status Page (iPhone Connected)
  • iPhone OpenVPN App showing connected
  • iPhone Ping App (Can ping 2 devices in my LAN)
  • iPhone trying to connect to Asus router login page (stuck loading)
  • iPhone disconnected from VPN and back on Wi-Fi local network (can connect to Router Login Page)

Adding the rest of the screenshots

Phone Connected to VPN Server.png Phone Pinging VPN Router.png Phone Pinging Synology NAS.png Phone Stuck Loading Asuswrt-Merlin Home Page.png Phone Connected to Wi-Fi can reach Login Page.png
 
Check the compression setting on the phone client. A successful connection with no traffic passing is a symptom of a compression setting mismatch.

You have LZ4 enabled on the server, so compression must be enabled on the client (and "none" means it is enabled), even if no compression is what is negotiated. Better to have "disabled" on both sides.
 
Wow that worked.

I disabled compression on OpenVPN server, exported a new .ovpn file, rebooted router (probably overkill), imported .ovpn to OpenVPN app on phones and phones are now behaving the same as PCs, can ping internal LAN IPs and can access the administrative pages. Thank You! :)
 
Glad that worked. Remember it will need to be disabled on the pc clients as well.
 

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top