OPNsense Forum

English Forums => Virtual private networks => Topic started by: mmaridev on August 04, 2021, 07:59:58 PM

Title: Cannot reach client LAN in OpenVPN site to site
Post by: mmaridev on August 04, 2021, 07:59:58 PM
Hi all,

I've setup a OpenVPN tunnel between two OPNSense firewalls. This the diagram:

LAN <-> Firewall A (OpenVPN client) <-> WAN <-> Firewall B (OpenVPN server) <-> other LAN/hosts

The status quo is that the clients in the LAN of A are able to ping/reach all hosts through the tunnel. Not the same from B, nor from the firewall itself or from the hosts behind it.
From packet capture on B I see packets with destination A's LAN exiting on the OpenVPN tunnel but on A they do not enter from the tunnel. Where are those packages left?
Tried both with peer to peer and remote access but nothing. I can add, I already ran into this problem in other setups.

Hope someone can help!
Best,
Marco
Title: Re: Cannot reach client LAN in OpenVPN site to site
Post by: mmaridev on August 26, 2021, 10:22:12 AM
Any idea?
Title: Re: Cannot reach client LAN in OpenVPN site to site
Post by: chemlud on August 26, 2021, 10:45:14 AM
If the tunnel is up and running, check FW-rules on both LANs (different subnet, I hope) and on openVPN tabs on BOTH sides...

Otherwise provide a network graph of your setup...