Имеем настроенный Openvpnserver на Pfsense (Mode: Peer to Peer ( SSL/TLS )) + подключенный к нему mikrotik.
полученный клиентом ip 10.0.78.2 с сервера 10.0.78.1 (Pfsense) пингуется, но когда пытаюсь пропингавать комп в локалке за микротиком или бридж микротика (192.168.11.1) пинг не идёт .
Настройки фаервола
0 ;;; Input
chain=input action=accept connection-state=established,related log=no
log-prefix=""
1 chain=input action=accept protocol=icmp log=no log-prefix=""
2 chain=input action=accept protocol=tcp src-address-list=WanAcceptIP
in-interface-list=WAN dst-port=8291 log=no log-prefix=""
3 ;;; DNS
chain=input action=accept protocol=udp in-interface-list=LAN dst-port=53
log=no log-prefix=""
4 ;;; Dostup Mikrotik iz Lan
chain=input action=accept protocol=tcp in-interface-list=LAN
dst-port=8291 log=no log-prefix=""
5 chain=input action=accept protocol=tcp in-interface-list=LAN dst-port=80
log=no log-prefix=""
6 ;;; Ping accept
chain=input action=accept protocol=icmp in-interface=bridge1 log=no
log-prefix=""
7 ;;; drop all input
chain=input action=drop connection-state=invalid log=no log-prefix=""
8 chain=input action=drop log=no log-prefix=""
11 chain=forward action=accept protocol=icmp log=no log-prefix=""
12 chain=forward action=accept out-interface=VpntoUSA in-interface-list=LAN
log=no log-prefix=""
13 chain=forward action=accept in-interface=VpntoUSA out-interface-list=LAN
log=no log-prefix=""
14 chain=forward action=accept in-interface-list=LAN out-interface-list=WAN
log=no log-prefix=""
15 chain=forward action=accept connection-state=established,related log=no
log-prefix=""
16 ;;; drop all forward
chain=forward action=drop connection-state=invalid log=no log-prefix=""
17 chain=forward action=drop log=no log-prefix=""
nat
0 chain=srcnat action=masquerade out-interface=ether1 log=no log-prefix=""
rout на микротик
[dracon@MikroTik] > /ip route print
Flags: D - DYNAMIC; A - ACTIVE; c - CONNECT, d - DHCP
Columns: DST-ADDRESS, GATEWAY, DISTANCE
DST-ADDRESS GATEWAY DISTANCE
DAd 0.0.0.0/0 94.180.57.254 1
DAc 10.0.78.0/24 VpntoUSA 0
DAc 10.0.78.0/32 VpntoUSA 0
DAc 94.180.57.0/24 ether1 0
DAc 192.168.11.0/24 bridge1 0
Подскажите в чем проблема ?