Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - eimann

#1
When pinging from the host (A) behind OPNsense to the Host (B) behind the Linux TS subnet router, I receive the traffic on host B, it replies and I see it leaving the Linux TS subnet router. However, I do not see the reply on the OPNsense TS interface, therefor never reaching host A.

When pinging from the host (B) behind Linux to the Host (A) behind the OPNsense, I do not receive any traffic on the OPNsense.
#2
I've got the same issue, unfortunately without a solution.
Tailscale ACL works, traffic also works on Linux (with disabled auto-SNAT as I want to preserve source IP).
However, when deploying on OPNsense, it breaks.

ping von freeradius => wlc tut (sehe icmp auf dem ts-sidecar in beide richtungen, auf der opnsense tailscale0 gar nix, auf dem lan interface aber schon)
ping von wlc => freeradius nicht, sehe icmp auf der opnsense tailscale0 ausgehen, auf ts-sidecar eingehend + ausgehend

ping from LAN A to LAN B
 traffic outgoing on OPNsense TS interface => incoming+outgoing on TS other subnet router <=> incoming+outgoing on LAN other Subnet Router

ping from LAN B to LAN A
 incoming on LAN other subnet router => outgoing on TS interface other Subnet Router => traffic NOT incoming on OPNsense TS interface

Firewall rules permit everything between these hosts/subnets. And of course with NAT it works, but as said before, losing source IPs which I need.