1
General Discussion / Re: IPSEC - remote site cant ping me, no pakets incoming on wan
« on: June 19, 2020, 08:28:45 am »
Problem solved.
TLDR: Turned out to be a issue with the cloud provider the opnsense is hosted at, which resulted in blocked ESP pakets.
They have a simplistic firewall that can be enabled which I used at the beginning of my experiments with this environment, but which I disabled some time ago. It looks like this firewall was active again without showing as being active in their API. My old rules where preserved which allowed UDP 500 and 4500 in, but not ESP. This explains, why their pakets came in after I sent pakets in their direction.
The other tunnels must have been affected also, but we didn't noticed this, as we are sending traffic to the remote peers on a regular basis.
TLDR: Turned out to be a issue with the cloud provider the opnsense is hosted at, which resulted in blocked ESP pakets.
They have a simplistic firewall that can be enabled which I used at the beginning of my experiments with this environment, but which I disabled some time ago. It looks like this firewall was active again without showing as being active in their API. My old rules where preserved which allowed UDP 500 and 4500 in, but not ESP. This explains, why their pakets came in after I sent pakets in their direction.
The other tunnels must have been affected also, but we didn't noticed this, as we are sending traffic to the remote peers on a regular basis.