OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • Site to Site after OPNsense 17.7.9 does not route the traffic
« previous next »
  • Print
Pages: [1]

Author Topic: Site to Site after OPNsense 17.7.9 does not route the traffic  (Read 4177 times)

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Site to Site after OPNsense 17.7.9 does not route the traffic
« on: December 12, 2017, 11:16:06 pm »
Dear all,
Today i have updated two hardware OPNsense to the latest version.
OPNsense 17.7.9_9-amd64
however after the update i noticed the site to site VPN seems not to route the traffic from the Client to the server

Server= 192.168.4.1
Client = 10.10.20.3

From the server i can connect to the client 10.10.20.3 on the other side of the country however from the client i can't ping or connect to the server.
when i trace route the traffic from the client to the server its comes back with time out.


Code: [Select]
C:\>tracert 192.168.4.1

Tracing route to 192.168.4.1 over a maximum of 30 hops

  1     *        *        *     Request timed out.
  2     *        *        *     Request timed out.
  3     *        *        *     Request timed out.

Can someone please help to point me to the right direction ?

Thank you
  4     *
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13988
  • Karma: 1211
    • View Profile
Re: Site to Site after OPNsense 17.7.9 does not route the traffic
« Reply #1 on: December 12, 2017, 11:55:47 pm »
Hi Julien,

For a marginally useful assessment we need to know the version you upgraded from where this was working ok?


Cheers,
Franco
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6348
  • Karma: 437
    • View Profile
Re: Site to Site after OPNsense 17.7.9 does not route the traffic
« Reply #2 on: December 13, 2017, 06:17:56 am »
With 17.7.9 (without _9) it had a similar problem. I disabled automatic ping host in P2 and then it was working .. but this should already be fixed
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: Site to Site after OPNsense 17.7.9 does not route the traffic
« Reply #3 on: December 13, 2017, 12:17:52 pm »
Quote from: franco on December 12, 2017, 11:55:47 pm
Hi Julien,

For a marginally useful assessment we need to know the version you upgraded from where this was working ok?


Cheers,
Franco
Hi Franco,
the previously version is the one before 17,7,9 we keep our firewall always updated so I believe it was 17,7,8


Thank you

mimugmail  the ping is not working and also we can't conenct or rdp the machines on the server side.
thank you
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

mimugmail

  • Hero Member
  • *****
  • Posts: 6348
  • Karma: 437
    • View Profile
Re: Site to Site after OPNsense 17.7.9 does not route the traffic
« Reply #4 on: December 13, 2017, 12:47:44 pm »
No, I meant if you have this feature active the tunnel doesn't work .. so removing anything in that line did the trick for me
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: Site to Site after OPNsense 17.7.9 does not route the traffic
« Reply #5 on: December 13, 2017, 01:01:01 pm »
Quote from: mimugmail on December 13, 2017, 12:47:44 pm
No, I meant if you have this feature active the tunnel doesn't work .. so removing anything in that line did the trick for me

Thank you mate, i dont have this really :(, from the server i can connect to the client and from the client not the server, i beleive the tunnel is both sides up only from the clients its not routing back to the server.
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: Site to Site after OPNsense 17.7.9 does not route the traffic
« Reply #6 on: December 14, 2017, 07:30:43 pm »
Can someone please advise as we need this tunnel up ?
firewall rules check no block from the client on the server firewall.
we have the same tunnels created with other office and it does works,
we noticed the only different between those two offices is this one using multi WAN and also we have some floating rules to allow the access to the gui over the multiple VLANS.

Can someone please advice where to look?

« Last Edit: December 14, 2017, 07:44:54 pm by Julien »
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

mimugmail

  • Hero Member
  • *****
  • Posts: 6348
  • Karma: 437
    • View Profile
Re: Site to Site after OPNsense 17.7.9 does not route the traffic
« Reply #7 on: December 14, 2017, 08:06:08 pm »
Do you use gateway rules? Try to disable multi WAN to find the error
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: Site to Site after OPNsense 17.7.9 does not route the traffic
« Reply #8 on: December 14, 2017, 08:14:00 pm »
Quote from: mimugmail on December 14, 2017, 08:06:08 pm
Do you use gateway rules? Try to disable multi WAN to find the error
Thank you for your answer,
what do you mean with Gateway rules? where I am supposed to check this ?
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

mimugmail

  • Hero Member
  • *****
  • Posts: 6348
  • Karma: 437
    • View Profile
Re: Site to Site after OPNsense 17.7.9 does not route the traffic
« Reply #9 on: December 14, 2017, 09:15:07 pm »
In Firewall rules set a gateway option .. like in the multi wan howto?
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: Site to Site after OPNsense 17.7.9 does not route the traffic
« Reply #10 on: December 15, 2017, 02:10:05 am »
Quote from: mimugmail on December 14, 2017, 09:15:07 pm
In Firewall rules set a gateway option .. like in the multi wan howto?
Thank you for your answer
just checked it and its not enabled,
i have disabled the multi WAN but still can't access the server side from the client side.
i really can't see any logs in the firewall !
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • Site to Site after OPNsense 17.7.9 does not route the traffic
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2