1
Virtual private networks / Wireguard - Connection is working but hosts in network do not have connectivity
« on: August 01, 2024, 06:10:29 pm »
I am currently setting up a site2site connection for testing. The Setup is the following
SITE A (up for testing):
- sits in the network of the site and has DHCP on WAN (192.168.x.x/24) provided by the networks router
- has a LAN Interface (10.10.x.x/17) that has no connected machines
SITE B:
- sits in the network as DMZ behind a router
- acts as DHCP DNS and devices in LAN are connected via LAN
- is where the client sits that tries to connect to a device in SITE A's WAN network
Now my problem is the following. The Wireguard connection seems to be working just fine. The OPNSense instances in both locations can ping, curl, etc. each others networks without any issues. However when I am trying to connect from a host in SITE B's network I cannot reach SITE A's hosts (except for the OPNSense instance which is reachable on its WAN as well as LAN address).
If I trace the packets it becomes clear that they reach SITE A. I also see them on the outgoing traffic of the WAN interface. But there does not seem to be a response. Even when I completely opened the WAN interface with ingoing and outgoing rules for the firewall I get nothing. I've been trying and researching all day but am pretty much lost at that point. Would be great if someone had an idea on what I could investigate
SITE A (up for testing):
- sits in the network of the site and has DHCP on WAN (192.168.x.x/24) provided by the networks router
- has a LAN Interface (10.10.x.x/17) that has no connected machines
SITE B:
- sits in the network as DMZ behind a router
- acts as DHCP DNS and devices in LAN are connected via LAN
- is where the client sits that tries to connect to a device in SITE A's WAN network
Now my problem is the following. The Wireguard connection seems to be working just fine. The OPNSense instances in both locations can ping, curl, etc. each others networks without any issues. However when I am trying to connect from a host in SITE B's network I cannot reach SITE A's hosts (except for the OPNSense instance which is reachable on its WAN as well as LAN address).
If I trace the packets it becomes clear that they reach SITE A. I also see them on the outgoing traffic of the WAN interface. But there does not seem to be a response. Even when I completely opened the WAN interface with ingoing and outgoing rules for the firewall I get nothing. I've been trying and researching all day but am pretty much lost at that point. Would be great if someone had an idea on what I could investigate