• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Shrew windows tunnel works, linux tunnel fails

Scheduled Pinned Locked Moved IPsec
13 Posts 3 Posters 4.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M Offline
    Metu69salemi
    last edited by Dec 13, 2011, 1:27 PM

    and what rules you have in vpn tunnel itself?

    1 Reply Last reply Reply Quote 0
    • E Offline
      El Snorro
      last edited by Dec 14, 2011, 1:41 PM

      @Metu69salemi:

      and what rules you have in vpn tunnel itself?

      On my pfsense box you mean?

      1 Reply Last reply Reply Quote 0
      • P Offline
        podilarius
        last edited by Dec 14, 2011, 1:53 PM

        Yes, you must have firewall rules in the VPN (racoon or openVPN) before it allows traffic to pass over the VPN.

        1 Reply Last reply Reply Quote 0
        • E Offline
          El Snorro
          last edited by Dec 14, 2011, 2:08 PM

          @podilarius:

          Yes, you must have firewall rules in the VPN (racoon or openVPN) before it allows traffic to pass over the VPN.

          I have configured my firewall rules correctly, since traffic can go trough the tunnel on a windows client.

          1 Reply Last reply Reply Quote 0
          • P Offline
            podilarius
            last edited by Dec 14, 2011, 2:24 PM

            Do you have iptables enabled on the linux system?

            1 Reply Last reply Reply Quote 0
            • E Offline
              El Snorro
              last edited by Dec 14, 2011, 2:26 PM

              No

              1 Reply Last reply Reply Quote 0
              • M Offline
                Metu69salemi
                last edited by Dec 14, 2011, 3:04 PM

                Then i don't know, sorry

                1 Reply Last reply Reply Quote 0
                • P Offline
                  podilarius
                  last edited by Dec 14, 2011, 3:07 PM

                  If you traceroute from the linux system to something behind the remote firewall, where does it hang in the path?

                  1 Reply Last reply Reply Quote 0
                  • E Offline
                    El Snorro
                    last edited by Dec 15, 2011, 9:27 AM

                    Enabled tunnel, gave command route and traceroute… (this is from a different location)

                    thijs@ltthijslinux ~ $ route
                    Kernel IP routing table
                    Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
                    172.28.201.0    *               255.255.255.0   U     1      0        0 eth0
                    192.168.78.0    *               255.255.255.0   U     0      0        0 tap0
                    192.168.0.0     192.168.78.1    255.255.254.0   UG    0      0        0 tap0
                    link-local      *               255.255.0.0     U     1000   0        0 eth0
                    default         172.28.201.254  0.0.0.0         UG    0      0        0 eth0
                    thijs@ltthijslinux ~ $ traceroute 192.168.0.1
                    traceroute to 192.168.0.1 (192.168.0.1), 30 hops max, 60 byte packets
                     1  * * *
                     2  * * *
                     3  * * *
                     4  * * *
                     5  * * *
                    
                    1 Reply Last reply Reply Quote 0
                    • P Offline
                      podilarius
                      last edited by Dec 15, 2011, 12:27 PM

                      Not sure … I tested my Shew in Linux and it worked. Though mine it not using a tunnel interface. I have use existing adapter and I have a policy of the remote network.

                      1 Reply Last reply Reply Quote 0
                      13 out of 13
                      • First post
                        13/13
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received