Routing issue over IPsec VTI with BGP

Started by r.laffont, April 15, 2026, 04:49:46 PM

Previous topic - Next topic
Hi everyone,

I have set up a IPsec tunnel between an OPNsense firewall and a Sophos firewall using VTI.
From the OPNsense VTI interface, I can successfully ping the Sophos VTI IP and vice versa.

I have initiated a BGP session between these two interfaces, and I can see the routes being exchanged on both firewalls.

However, from a PC behind the OPNsense, I am unable to ping or run a traceroute to the Sophos LAN interface.
I have already created the necessary firewall rules to allow traffic on both sides.

Thank you in advance for your help.
Romain