Hoping for some help please.
I read this guide to setup remote user access Configure Remote User Access using OpenVPN and chose a vlan which has my NAS
I have an android phone (grapheneos) and installed OpenVPN for Android (by Arne Schwabe), imported both full and split profiles from the B20X (latest firmware)
I can connect the tunnel with either full or split profile. In the router page connected clients, I can see my phone has connected and has been assigned a correct IP for that VLAN, but I can’t connect the phone to anything.
There is also a pi on this vlan (connected locally) and that can connect to the NAS and ping it, so local routing is fine. But the pi cannot ping the phone.
The phone has the app termux giving me a command prompt and I cannot ping from the phone to the nas or pi.
There is limited outbound connectivity on this vlan (some specific ports are allowed for the NAS like time. The pi which I use to administer the NAS has no internet connectivity).
I was hoping to have this vlan for the purpose to VPN in and use the NAS for music, synching files etc but have no outbound - hopefully making this a safe (ish) way to get access to my NAS.
I’ve searched through the forum and some posts have come close to a solution
There’s no port forwarding setup (I previously port forwarded 443 and used a reverse proxy in combination with different sub domains for different services from the NAS like movies.mydomain.com and files.mydomain.com, but with a VPN I hoped to not need to forward any ports)
The firewall rules are not restrictive within the vlan.
I have a block all rule within “Inbound Firewall Rules” & “Local Service Firewall Rules” both set to log events and nothing is showing as being blocked when I try to ping from the phone or connect to the nas with a browser.
I think it all points to a routing problem of some kind but I’m at a loss if this is a fix that is applied on the router side or app on the phone.
If I make changes in the router, do I need to regenerate the OpenVPN profiles?
Within the LAN settings for this VLAN, I have DNS servers assisned automatically, but my pi which has no actual access to the internet so cannot see those DNS servers can access the NAS just fine.
Any help or pointers will be greatly received