Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - matthewdu92

#1
Hi there

I have an issue in building a second Client to site VPN on an Opnsense where a Site to site vpn server already exists.

In the map attached you can see the actual infrastructure.

Site to Site work like a charm and I can reach the "WIN2" machine from the "WIN1" machine (Ping and RDP)

If I create a second VPN server for users to connect, on a different acces port 1195 and I just enable IT (no need to mount any tunnel :
- I can mount the connection from public to RT1
- 1rst VPN S2S connection do not fall 


but the issue is that I cannot reach the 192.168.60.0 network any more after from WIN1 machine (no ping no RDP)
With 2nd VPN server connection, I can reach only WIN1 and RT1 but nor  192.168.60.0 .

At the point where I just disable it (with the Play button), all thing are getting well as before.

Any idea with this key things ? I can give you more info if needed
#2
Hi guys

First post, I m looking for some help  :D

I did setup that :

Orange ISP > opnsense > LAN for company + VLAN20 for guests

LAN : LAN is on igb0 with 192.168.100.1 ip et give 192.168.100.0/24 dhcp address
VLA20: VLAN20 is also on igb0 but is not the point here ; works well, cannot reach the LAN and it's ok.
WAN1: ORANGE ISP is on igb1 with 192.168.1.20 interface ip
WAN2 : nothing, igb2 is free today

LAN and VLAN20 can well surf on the internet through WAN 2

What I want to setup now:
We also have a SFR ISP access which cast internet access + VPN Access to another site (location) we have
SFR access give 192.168.2.0/24 address on site 1
We can reach the other site by joining 192.168.1.0/24 style addresses

I'd like to plug SFR on igb2 and make all requests to 192.168.1.0/24 going on WAN 2 and being processed by SFR access to reach the site

I know I have to change the original Orange IP which Is 192.168.1.0/24 in order not to have 2 same subnet but I think I might add some route rules and I don't know what rules ?

I think my request will appear easy for most of you but not for me  :'(

Thanks a lot for your help

Sorry if I forgot some info, just ask me for sure !

Mathieu