OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Ping from firewall over IPSEC
« previous next »
  • Print
Pages: [1]

Author Topic: Ping from firewall over IPSEC  (Read 4061 times)

alfemann

  • Newbie
  • *
  • Posts: 15
  • Karma: 0
    • View Profile
Ping from firewall over IPSEC
« on: January 10, 2019, 12:17:13 pm »
I have a functioning IPSEC-tunnel up running on an OPNsense 17.7.4, and traffic between machines on either side is running perfectly.

I want to use an LDAP-server on the remote side of the IPSEC tunnel for authentication (for incoming openvpn roadwarrior clients). When I try to set this up as a server in OPNsense menu, there is no response from LDAP server. I then tried to ping the server from the OPNsense - no reply.
Doing ping or LDAP from any client on the LAN-side of the OPENsense - works fine.

What on earth could I be missing ??
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17705
  • Karma: 1618
    • View Profile
Re: Ping from firewall over IPSEC
« Reply #1 on: January 10, 2019, 04:13:38 pm »
#ping -S LANIP LDAPIP


Cheers,
Franco
Logged

akron

  • Jr. Member
  • **
  • Posts: 57
  • Karma: 2
    • View Profile
Re: Ping from firewall over IPSEC
« Reply #2 on: September 27, 2019, 09:17:19 pm »
Quote from: franco on January 10, 2019, 04:13:38 pm
#ping -S LANIP LDAPIP


Cheers,
Franco

Same behaviour on last OPNsense 19.7.4

from lan subnet across the IPsec tunnel to remote subnet works, but doesn't ping or connectivity from the firewall IP itself (Goes over the default WAN up and not via the IPSec Tunnel), which if you want to connect the firewall to a remote over the tunnel LDAP server doesn't work

any workaround on this?

Cheers
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Ping from firewall over IPSEC
« Reply #3 on: September 27, 2019, 10:02:59 pm »
Add WAN IP to a second Phase2 :)
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

akron

  • Jr. Member
  • **
  • Posts: 57
  • Karma: 2
    • View Profile
Re: Ping from firewall over IPSEC
« Reply #4 on: September 28, 2019, 01:19:12 pm »
Quote from: mimugmail on September 27, 2019, 10:02:59 pm
Add WAN IP to a second Phase2 :)

Not sure if is clear?


what do I have to do so the FW endpoint ping the remote subnet ?

Cheers
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Ping from firewall over IPSEC
« Reply #5 on: September 28, 2019, 02:37:26 pm »
You add a second Phase2, left wanip/32, right remote subnet
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

akron

  • Jr. Member
  • **
  • Posts: 57
  • Karma: 2
    • View Profile
Re: Ping from firewall over IPSEC
« Reply #6 on: September 28, 2019, 02:57:01 pm »
Quote from: mimugmail on September 28, 2019, 02:37:26 pm
You add a second Phase2, left wanip/32, right remote subnet

add a second phase 2 with my WAN IP or Peer WAN IP?

only phase 1 has the peer WAN IP at the moment.

there isn't a more reliable way to get the FW to ping the remote subnet as all endpoints do passing through the firewall?

Cheers
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Ping from firewall over IPSEC
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2