Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Destination Host Unreachable

    Scheduled Pinned Locked Moved OpenVPN
    8 Posts 3 Posters 563 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      TomNick
      last edited by

      Hi everybody,

      I did set up openvpn peer to peer and it is connected. As soon as I am trying to ping he other peer I am getting:

      PING 192.168.21.1 (192.168.21.1) 56(84) bytes of data.
      From 192.168.1.1 icmp_seq=1 Destination Host Unreachable
      

      Setup Server:

      brave_screenshot10.png
      brave_screenshot11.png
      brave_screenshot12.png
      brave_screenshot13.pngbrave_screenshot14.png
      brave_screenshot15.png

      Setup Client:

      brave_screenshot20.png
      brave_screenshot21.png
      brave_screenshot22.png
      brave_screenshot23.png
      brave_screenshot24.png
      brave_screenshot25.png

      Firewall:

      brave_screenshot26.png
      brave_screenshot27.png

      pfsense is running on proxmox with a seperate IP

      I have been sitting here for hours to figure out what could be wrong. Does anybody have any idea what I might have overlooked? Thanks for some help

      V GertjanG 2 Replies Last reply Reply Quote 0
      • V
        viragomann @TomNick
        last edited by

        @TomNick
        You have stated 192.168.21.0/24 as local and remote network in the server setting.
        If you really have the same subnet at both sites they will be unable to communicate. You will have to change it at one site. Alternatively you can nat one, but changing one is highly recommended.

        1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan @TomNick
          last edited by

          @TomNick

          Also :

          This one :

          77d188f9-b924-4128-bc9d-b9af3c419a76-image.png

          if you have pfBlockerng(devel) installed, be aware that it used by default the same network.
          Thus : problems ...

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          1 Reply Last reply Reply Quote 0
          • T
            TomNick
            last edited by

            I experimented and changed the server mode to "Peer to Peer (Shared Key)" and that works like a charm. So the problem seems to be in SSL/TLS but still not figured out what exactly it is.

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @TomNick
              last edited by

              @TomNick
              If shared key works, while SSL didn't you were rather missing the client specific override.

              T 1 Reply Last reply Reply Quote 0
              • T
                TomNick @viragomann
                last edited by

                @viragomann said in Destination Host Unreachable:

                @TomNick
                If shared key works, while SSL didn't you were rather missing the client specific override.

                I did that, I was just missing to post it:

                brave_screenshot30.png

                V 1 Reply Last reply Reply Quote 0
                • V
                  viragomann @TomNick
                  last edited by

                  @TomNick
                  You have to state a usable tunnel IP for the client here. The network address is wrong.
                  The first IP is used by the server. So in a /24 it has to be above of 1.

                  1 Reply Last reply Reply Quote 0
                  • T
                    TomNick
                    last edited by TomNick

                    Solved
                    Setup from scratch, now it is working, I have probably done something wrong with the certificate. Thanks all for help

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.