Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec site-to-site VPN established, but I can't seem to touch their subnet

    Scheduled Pinned Locked Moved IPsec
    3 Posts 2 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      azcire
      last edited by

      Weird problem here… The purpose of this VPN is to give some machines (192.168.9.0 through 192.168.9.15) on my network (192.168.9.0/24) access an intranet site on a client's network. I've been using the guide on the Pfsense wiki to set things up… Here's the summary of what has been done so far:

      192.168.9.0/28 --> PFsense (192.168.9.1) --> WAN (68.X.X.X) --> IPSEC TUNNEL --> Remote Host (200.X.X.X) --> Intranet site (172.X.X.X)

      I have the VPN established with a green light on the status page.



      Here is my firewall rule for IPsec:

      Here are my firewall rules to ensure the remote host can connect to my WAN:

      When I try to access 172.X.X.X in a browser (or ping) from a machine within my subnet specificed in the IPsec config, I get nothing. I see no entries in the firewall for any of the IPs mentioned above.

      What should I look at next? I feel like I must be missing something obvious since the IPsec connection is established and green.

      1 Reply Last reply Reply Quote 0
      • A
        azcire
        last edited by

        This is becoming more urgent of an issue for me… If you can solve this with me today or tomorrow, PM me and I'll point you to the elance job or we can do the transaction on paypal. Willing to pay $50 for a quick resolution.

        1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          There is data on the SAD entries going from you to the remote site - there is no data on the return SAs. That implies that they are blocking the traffic or it's being ignored/misrouted on the return. You side may be setup right. I'd focus on the remote.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.