OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • IPsec VPN on mobile Question
« previous next »
  • Print
Pages: [1]

Author Topic: IPsec VPN on mobile Question  (Read 4637 times)

csmall

  • Full Member
  • ***
  • Posts: 121
  • Karma: 5
    • View Profile
IPsec VPN on mobile Question
« on: June 26, 2019, 01:49:36 pm »
How can I prevent the tunnel from being split tunnel? I want to force all traffic over the tunnel.

I'm using ikev2 and strong swan client on Android.

My main goal is using my pihole for dns remotely. So if that is possible without forcing all traffic over the tunnel then if be happy with that as well.

Any help much appreciated.

Right now it is split tunnel
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: IPsec VPN on mobile Question
« Reply #1 on: June 26, 2019, 03:03:26 pm »
I don't get it, when you set your internal DNS as system DNS, why do you need to route all traffic over the tunnel?
In strongswan app you can set the specific routes to tunnel trough network, they have to match on both sides and then you can also tunnel ALL traffic.
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

csmall

  • Full Member
  • ***
  • Posts: 121
  • Karma: 5
    • View Profile
Re: IPsec VPN on mobile Question
« Reply #2 on: June 26, 2019, 07:52:34 pm »
In phase2 I have the network set to lan but I tried switching it to network 0.0.0.0/0 and then on strong swan client I tired adding 0.0.0.0/0 as a subnet to send over the tunnel.

I was unable to access the internet at that point on the mobile device but I was able to still get to the opnsense web interface and I ternal resources by ip.
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: IPsec VPN on mobile Question
« Reply #3 on: June 26, 2019, 08:25:30 pm »
You need outbound Nat for your tunnel network.
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

csmall

  • Full Member
  • ***
  • Posts: 121
  • Karma: 5
    • View Profile
Re: IPsec VPN on mobile Question
« Reply #4 on: June 27, 2019, 02:17:11 pm »
Thanks. I tried adding that as well and internet access still doesn't work over the tunnel. I'll have to dig deeper.. maybe it is being blocked somewhere.

I get the feeling it may be dns related so I'll try to go to an IP and see if I can get out. That should point me in the right direction
Logged

csmall

  • Full Member
  • ***
  • Posts: 121
  • Karma: 5
    • View Profile
Re: IPsec VPN on mobile Question
« Reply #5 on: June 27, 2019, 07:43:27 pm »
Quote from: csmall on June 27, 2019, 02:17:11 pm
Thanks. I tried adding that as well and internet access still doesn't work over the tunnel. I'll have to dig deeper.. maybe it is being blocked somewhere.

I get the feeling it may be dns related so I'll try to go to an IP and see if I can get out. That should point me in the right direction

It works now. Thanks again!
Logged

ChrisBondy

  • Newbie
  • *
  • Posts: 5
  • Karma: 1
    • View Profile
Re: IPsec VPN on mobile Question
« Reply #6 on: July 02, 2019, 11:45:38 pm »
How did you get it work? I've been trying. with Android and Mac Mobile.
Both connect without any issues. I sent both to use 8.8.4.4, internet works.
But can't see or connect to anything inside the network.
 I followed the road warrior document.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • IPsec VPN on mobile Question
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2