OPNsense Forum

Archive => 17.1 Legacy Series => Topic started by: jaco.vandenberg on June 26, 2017, 09:19:42 pm

Title: IPsec tunnel blocks local management
Post by: jaco.vandenberg on June 26, 2017, 09:19:42 pm
Hi,

An IPsec tunnel used for a site-to-site VPN does not allow to manage the opnsense instance once the tunnel is up.
The opnsense is on 10.200.5.1: as soon as the tunnel is started, i can only manage the opensense webinterface from the other site: so from the other side of the tunnel, backwards through to tunnel  :-) !

All routing works as expected, only the fact that I can not manage opnsense through the gateway interface address as soon as the tunnel is started, appears odd to me.

the Anti-Lockout Rule is in place and enabled.

has anybody observed this ?

version 17.1.8 on AMD64
Title: Re: IPsec tunnel blocks local management
Post by: Julien on July 01, 2017, 01:43:28 am
have you checked the rules on the IPSec interface?
next week I am building a replica with two firewall and I will have to configure this.
Title: Re: IPsec tunnel blocks local management
Post by: jaco.vandenberg on July 03, 2017, 12:10:34 pm
There is an any-to-any rule on the tunnel, that should apply on the traffic within the tunnel.

the management should not be influenced by the tunnel's settings, it should remain available on the local LAN interface in my opinion. Right now, as soon as the tunnel is started, the management is broken.
Let us know what your findings are.
Title: Re: IPsec tunnel blocks local management
Post by: Julien on August 27, 2017, 12:51:24 pm
i just have build this and i can really manage both firewall from both sites.
have you checked the firewall rules from both sides?
let me double check this with you.
when the tunnel is up can you access the devices behind the tunnel right ?
are the remote network on both firewalls not the samen?
i am sure it something with your configuration as i just build two sites and i can access both firewalls using their LAN IP from both sides.
check this again https://docs.opnsense.org/manual/how-tos/ipsec-s2s.html?highlight=site%20site