OPNsense Forum

English Forums => Virtual private networks => Topic started by: jackc on November 12, 2020, 09:46:47 PM

Title: VPN does not communicate LAN
Post by: jackc on November 12, 2020, 09:46:47 PM
Good afternoon guys, I have a VPN peer to peer communicating just fine, but the client network does not access the main network and in the firewall logs it informs me "let out anything from firewall host itself" would anyone have any tips?
he informs me of this "error" every time networks try to communicate.
(https://uploaddeimagens.com.br/imagens/2u99_EA)
Title: Re: VPN does not communicate LAN
Post by: bartjsmit on November 13, 2020, 07:44:40 AM
Quote from: jacksonconti on November 12, 2020, 09:46:47 PM
would anyone have any tips?

Always check three things:
1. parity between the VPN devices - same crypto, compression, subnet definition, etc.
2. firewall rules on all firewalls that allow the traffic
3. routes on both endpoints and all the routers along the way

Number 3 is most often overlooked

Bart...
Title: Re: VPN does not communicate LAN
Post by: Gauss23 on November 13, 2020, 09:11:46 AM
Quote from: jacksonconti on November 12, 2020, 09:46:47 PM
Good afternoon guys, I have a VPN peer to peer communicating just fine, but the client network does not access the main network and in the firewall logs it informs me "let out anything from firewall host itself" would anyone have any tips?
he informs me of this "error" every time networks try to communicate.

Oh come on...do you really think with this small amount of information, that someone will be able to give you some hints?

We would need a graphical network plan (with networks and IPs), what type of VPN (IPsec, OpenVPN, WireGuard) you are using and if you have admin access to the other side of the VPN tunnel.

Creating a graphical network plan helps you to understand your network and maybe you'll see your mistake already while creating it.