OpnSense to OpnSense VPN

Started by romey2042, September 09, 2019, 09:06:30 PM

Previous topic - Next topic
So I have a OpnSense box at my house and it is connected to an OpnSense VM in the Azure cloud. I have them both configured the same and the IPSec VPN is up. From the Azure side I can ping the other side, however from home I can not ping anything in azure. I have the routes set up. Am I missing something, could it be because Azure is nat'd and I need something there? I have the NSG set to allow all traffic in.


Has anyone got this to work?

Is this a routed ipsec tunnel? Can you check if you have ipsec networks in automatic outbound nat (which doesn't work)?

I had basically this same issue doing a lab with Opnsense to Opnsense (both VM's within Azure). I could ping both sides of the tunnel interfaces from within each Opnsense VM, but nothing else.  My issue was having not enabled 'IP Forwarding' on the NIC's of each VM within the Azure portal.  Once that was completed, everything was accessible on both sides.

"Any network interface attached to a virtual machine that forwards network traffic to an address other than its own must have the Azure Enable IP forwarding option enabled for it. "


Hopefully this helps someone else.