Bespoke cloud platformVM hosting OpnSense - 192.168.1.1 (ASN 64514, BGP advertised 192.168.1.0/24)VM web server - 192.168.1.100AWS Site-to-Site VPN (AWS ASN 64512)VM - 172.31.86.32OpnSense > Firewall > Rules > IPsecProtocol: IPv4Source: *Port: *Destination: LAN netPort: *Gateway: *OpnSense > Firewall > Rules > LANDefault allow LAN to any IPv4 and IPv6.OpnSense > Firewall > Rules > WANAllow 500 (ISAKMP), 4500 (IPsec NAT-T), 179 (BGP).Routing > Diagnostics > BGP > IPv$ Routing TableValid Best Internal Network Next Hop Metric LocPrf Weight Path OriginY N N 172.31.0.0/16 169.254.220.77 200 0 0 64512 IGPY Y N 172.31.0.0/16 169.254.135.37 100 0 0 64512 IGPY Y N 192.168.1.0/24 0.0.0.0 0 0 32768 Internal IGP
OpnSense > Routing > BGP > GeneralNetwork: 192.168.1.0/24Select the network to advertise, you have to set a Null route via System -> Routes
Destination, Target, Status, Propagated0.0.0.0/0, igw-27d7295d, Active, No172.31.0.0/16, local, Active, No192.168.1.0/24, vgw-01c10b23ec5e24488, Active, Yes
25 20.305718 172.31.40.15 192.168.1.100 TCP 66 [TCP Retransmission] 49418 → 80 [SYN, ECN, CWR] Seq=0 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=125 20.305718 172.31.40.15 192.168.1.100 TCP 66 [TCP Retransmission] 49418 → 80 [SYN, ECN, CWR] Seq=0 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=127 20.557705 172.31.40.15 192.168.1.100 TCP 66 [TCP Retransmission] 52171 → 80 [SYN, ECN, CWR] Seq=0 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=1
Tracing route to ip-192-168-1-100.ec2.internal [192.168.1.100] over a maximum of 30 hops: 1 8 ms 8 ms 8 ms 169.254.126.28 2 * * * Request timed out. 3 * * * Request timed out....
Tunnel Number Outside IP Address Inside IPv4 CIDR Inside IPv6 CIDR Status Status Last Changed DetailsTunnel 1 4.279.84.223 169.254.126.26/30 - UP July 12, 2021 at 1:43:21 PM UTC+1 1 BGP ROUTESTunnel 2 100.20.252.220 169.254.222.26/30 - UP July 12, 2021 at 1:43:16 PM UTC+1 1 BGP ROUTES
Destination Target Status Propagated172.31.0.0/16 local Active No0.0.0.0/0 igw-67d7675d Active No192.168.1.0/24 vgw-01b10b25ec5e28844 Active Yes