OPNsense Forum

Archive => 17.7 Legacy Series => Topic started by: whoppi on January 27, 2018, 03:47:18 pm

Title: OpenVPN client connect to site-to-site openvpn network
Post by: whoppi on January 27, 2018, 03:47:18 pm
 Hi evryone, i have a question regarding OpenVPN. I have a firewall1 with one OpenVPN Server where clients connect to. This firewall1 ist connected as a site-to-site openvpn client to our firewall2. If i connect as a client to the vpn server of firewall1 i cant reach the the network of the firewall2. Is there a special thing to do. I have configured all local and remote networks.

I can connect to the firewall2 network from the local lan of firewall1 but not from openvpn client connected to firewall1

i can see in my routes of client connected through vpn, that the routes are pushed corectly.

if i try to make traceorute on the firewall1, i can reach the datacenter networks, but it i choose the source for traceroute to vpn servers entwork, then it do not work and i receive ony  * * * at traceroute

if i trace the site-to-site connection i acnt see that the pings are leaving the firewall1 to site-to-site. Any advice where i can look
Title: Re: OpenVPN client connect to site-to-site openvpn network
Post by: whoppi on February 19, 2018, 05:59:34 am
Anybody who can help me?
Title: Re: OpenVPN client connect to site-to-site openvpn network
Post by: bartjsmit on February 19, 2018, 08:26:08 am
Hi Whoppi,

Make sure your routes are correct both ways; the targets need to have a route back to the source for all subnets. Mind that there are at least four in play; datacenter - tunnel1 - opnsense - tunnel2 and possibly one for the client.

Capture a ping run on the OPNsense firewall and have a look at wireshark. Remember to set the source IP address in ping.

Bart...