Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Site-to-Site OpenVPN: Ping Works HQ Firewall to DC Client, but Not DC Firewall to HQ Firewall

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 2 Posters 674 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      viragomann @PlanetToysUtah
      last edited by

      @PlanetToysUtah
      Since you didn't mention the client specific override, I guess, you're missing it.

      P 1 Reply Last reply Reply Quote 0
      • P
        PlanetToysUtah @viragomann
        last edited by

        @viragomann do i need that?

        V 1 Reply Last reply Reply Quote 0
        • V
          viragomann @PlanetToysUtah
          last edited by

          @PlanetToysUtah
          If there is only a single client connecting to the server AND you can forgo to use DCO, you can set the tunnel network mask to /30 and it will work without a CSO.

          P 1 Reply Last reply Reply Quote 0
          • P
            PlanetToysUtah @viragomann
            last edited by

            @viragomann i head if it's in /30 that isn't good for site-site VPN's also i added a DCO and it still didn't work

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @PlanetToysUtah
              last edited by

              @PlanetToysUtah said in Site-to-Site OpenVPN: Ping Works HQ Firewall to DC Client, but Not DC Firewall to HQ Firewall:

              i head if it's in /30 that isn't good for site-site VPN's also i added a DCO and it still didn't work

              ?
              DCO is a check box in the the settings of pfSense+.
              And it's not compatible with a /30 tunnel mask.

              So what did you actually?

              1 Reply Last reply Reply Quote 0
              • P
                PlanetToysUtah
                last edited by

                ah ok i have pfsense CE i got the ping from HQ to DC working but not DC to HQ i can ping 192.168.11.1 from DC but no clients on the next hop over at 192.168.5.0/24

                P 1 Reply Last reply Reply Quote 0
                • P
                  PlanetToysUtah @PlanetToysUtah
                  last edited by

                  @PlanetToysUtah
                  Also i did CSO (Clinet Specific Overrides) and added the correct routes and that worked. but still having issues with dc to HQ 5.0/24 network

                  V 1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @PlanetToysUtah
                    last edited by

                    @PlanetToysUtah
                    In the CSO you have to state the client sides networks at "remote networks" and once again in the server settings.

                    If it doesn't work either, set the servers log verbosity level to 4. Then reconnect the client and check the logs for regarding entries.
                    The server then logs if the CSO was applied and if the routes for the client networks were added inside OpenVPN.

                    1 Reply Last reply Reply Quote 0
                    • P
                      PlanetToysUtah
                      last edited by

                      @viragomann I got all that fixed now the DC VM's can't ping any local system except for 192.168.11.1 but they can't reach 192.168.5.0/24

                      P 1 Reply Last reply Reply Quote 0
                      • P
                        PlanetToysUtah @PlanetToysUtah
                        last edited by

                        @viragomann You have any idea why I still can't ping from DC to HQ LAN?

                        V 1 Reply Last reply Reply Quote 0
                        • V
                          viragomann @PlanetToysUtah
                          last edited by

                          @PlanetToysUtah
                          Is the CSO applied??
                          Please show the log.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.