OPNsense Forum

English Forums => 26.1 Series => Topic started by: d4rkd3n1337 on February 03, 2026, 01:54:43 PM

Title: IPSec VTI and Reply-TO problem
Post by: d4rkd3n1337 on February 03, 2026, 01:54:43 PM
Hello!
I have the following topology:

VPS (iptables) <‑‑ IPSec VTI <‑‑ OPNsense <‑‑ WebServer
3.3.3.3 | [10.64.0.2/30 <‑‑ 10.64.0.1/30] | 2.2.2.2 <‑‑ 192.168.100.4


The tunnel is up and functioning.

When an inbound packet arrives from the VPS side, I can see it reach OPNsense and then be delivered to the WebServer (TCP SYN). However, the client never receives a reply.

What I have tried:

1) Policy‑Based Routing (PBR) on the WebServer's network – set 192.168.100.4 to use ipsecX(10.64.0.2) as the next‑hop. Traceroute shows the traffic follows the expected path.
2) Reply‑to rule on enc0 (the IPSec interface) – added reply‑to ipsecX(10.64.0.2) in the allow rules. (src: any, src_port: any, dst: 192.168.100.4, dst_port: 443, reply_to: ipsecX(10.64.0.2).
tcpdump on enc0 shows the outbound traffic attempting to go to the client (192.168.100.4 → client IP). No return traffic is observed on the opposite side of the tunnel. The VPS has IP forwarding enabled, NAT configured to its public IP, and port‑forwarding rules in place. There are no firewall rules that would block the traffic.

Observation: If I add a static route on OPNsense such as client‑IP/32 → 10.64.0.2, the communication works immediately.

Question: Any ideas why the reply traffic does not traverse the tunnel without the explicit host route? Could my reply‑to configuration be incorrect?