# Unable to interface with DietPi over personal VPN

**URL:** https://dietpi.com/forum/t/unable-to-interface-with-dietpi-over-personal-vpn/19909
**Category:** Troubleshooting
**Created:** [16 April 2024 11:55 UTC](https://dietpi.com/forum/t/unable-to-interface-with-dietpi-over-personal-vpn/19909 "2024-04-16T11:55:59Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Arzepp](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/a/f6c823/32.png) [@Arzepp](https://dietpi.com/forum/u/Arzepp)
#### Post date: [16 April 2024 11:55 UTC](https://dietpi.com/forum/t/unable-to-interface-with-dietpi-over-personal-vpn/19909/1 "2024-04-16T11:55:59Z")

</div>

- DietPi version |  
G\_DIETPI\_VERSION\_CORE=9  
G\_DIETPI\_VERSION\_SUB=3  
G\_DIETPI\_VERSION\_RC=0  
G\_GITBRANCH=‘master’  
G\_ITOWNER=‘MichaIng’

- Distro version |  
bullseye 1

- Kernel version |  
Linux DietPiVPN 6.1.21-v7+ #1642 SMP Mon Apr 3 17:20:52 BST 2023 armv7l GNU/Linux

- Architecture |  
armhf

- SBC model |  
RPi 3 Model B+ (armv7l)

I have DietPi running on a raspberry pi 3B+ on my home network (10.0.30.0/24). I use it for sonarr, radarr, transmission and a VPN connection to NordVPN using the dietPi’s own software (as well as the kill switch enabled). On my home network I also have a Firewalla device, acting as a router. On this, I have a VPN server running so I can VPN into my home network when I’m away. The Firewalla uses Wireguard VPN software (network 10.1.30.0/24).

I however have found that when I VPN through the Firewalla into my home, AND the VPN to NordVPN on my dietpi is connected, I am unable to connect to web interfaces of anything running on the Pi (sonarr, radarr and transmission), and I also am unable to SSH into the Pi. If I disconnect the dietpi VPN, I can instantly access all of these services when away no problem.

I am also running a SynologyNAS (network also 10.1.30.0/24), which among other things I use for a different VPN server. Its VPN server uses L2TP/IPSec. Whenever I’m away from home and connect to my home LAN using the Synology VPN server, I can access the DietPi no problem, irrespective of if the DietPi VPN Nord connection is running or not.

When dietpi VPN is connected, sudo iptables -S looks like the following:

> -P INPUT DROP  
> -P FORWARD DROP  
> -P OUTPUT DROP  
> -A INPUT -i lo -j ACCEPT  
> -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT  
> -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT  
> -A INPUT -p tcp -m tcp --dport 8989 -j ACCEPT  
> -A INPUT -p tcp -m tcp --dport 7878 -j ACCEPT  
> -A INPUT -p tcp -m tcp --dport 9091 -j ACCEPT  
> -A INPUT -p tcp -m tcp --dport 9117 -j ACCEPT  
> -A OUTPUT -o lo -j ACCEPT  
> -A OUTPUT -o tun0 -j ACCEPT  
> -A OUTPUT -d 192.168.0.0/16 -j ACCEPT  
> -A OUTPUT -d 172.16.0.0/12 -j ACCEPT  
> -A OUTPUT -d 10.0.0.0/8 -j ACCEPT  
> -A OUTPUT -d 84.17.39.218/32 -p udp -m udp --dport 1194 -j ACCEPT

I’m not the most technically literate user, so the reading I’ve done on here and reddit has not turned up anything useful.

I was wondering if someone could point me in the right direction in regard to troubleshooting this problem. I find it odd that I can VPN to home using L2TP/IPSec and still interface with dietpi, but can’t over wireguard.

Thanks in advance

---

<div class="post-metadata">

### Author: ![trendy](https://dietpi.com/forum/user_avatar/dietpi.com/trendy/32/61_2.png) [@trendy](https://dietpi.com/forum/u/trendy)
#### Post date: [16 April 2024 16:13 UTC](https://dietpi.com/forum/t/unable-to-interface-with-dietpi-over-personal-vpn/19909/2 "2024-04-16T16:13:27Z")

</div>

A few of them.

> [@Wireguard server + OpenVPN client, again](https://dietpi.com/forum/t/wireguard-server-openvpn-client-again/14474/6):
>
> This one makes sure the wireguard will use the ISP and not the VPN. Then you need to masquerade wireguard IPs to the eth0 IP when the destination is in the lan, or to the openvpn client when the destination is the internet.

> [@Need VPN iproute help](https://dietpi.com/forum/t/need-vpn-iproute-help/19089/10):
>
> Given the requirement to route only the hotspot over vpn, I would suggest the following. Filter the default gateway from the OpenVPN client. cat \<\< EOF \>\> /etc/openvpn/client.conf pull-filter ignore redirect-gateway route-nopull EOF Now your default gateway remains the eth1 after the VPN is up. Isolate the hostspot and route it over the VPN ip rule add from 192.168.42.0/24 lookup 42 ip route add default via 10.6.19.1 dev tun1 table 42 Fix the firewall iptables -t nat -A POSTROUTING -s 1…

> [@Wireguard, iptables and access to dietpi from another VLAN](https://dietpi.com/forum/t/wireguard-iptables-and-access-to-dietpi-from-another-vlan/15939):
>
> I am trying to ssh to DietPi that has a running Wireguard client from a PC on another VLAN. As my issue seems to be closely related with what was discussed in this topic: [Wireguard Client & iptables](https://dietpi.com/forum/t/wireguard-client-iptables/13356) I have based my iptables rules on the proposed solutions there. However, while the solution works fine as long as I am accessing DietPi from a machine that is on the same VLAN, the access is denied when I move to another VLAN. I have the following setup. PC on VLAN 1, Dietpi running Wireguard and Mo…

---

<div class="post-metadata">

### Author: ![system](https://dietpi.com/forum/uploads/default/original/1X/7e1021de2213860bce185915ce2c1786e56490ec.png) [@system](https://dietpi.com/forum/u/system)
#### Post date: [12 October 2024 04:14 UTC](https://dietpi.com/forum/t/unable-to-interface-with-dietpi-over-personal-vpn/19909/3 "2024-10-12T04:14:04Z")

</div>

This topic was automatically closed 178 days after the last reply. New replies are no longer allowed.
