Half working routing
-
I have a AWS site and a Local Office Site. I have OpenVPN setup with working connections, I also have BGP configured for routing.
Everything is connected. However routing is acting a bit weird.
I am able to ping From the local office site to AWS just fine…..however I am NOT able to ping from the AWS site to the local office.
Not sure what I am missing.
I tried adding a static route on the AWS side and added the right networks to the security groups. Still not able to route.
Pinging anything in the 173.31.0.0/16 from the 10.0.96.0/19 network works just fine, but pinging anything in the 10.0.96.0/19 from anywhere in the 173.31.0.0/16 network fails.
Pinging from the AWS PfSense works to anything in the 10.0.96.0/19 network, and pinging from the local Pfsense to 173.31.0.0/16 works as well if done from the PFsense.
Not sure what I am missing....
Diagrams attached.
Any suggestions.....Don't have full AWS support plan yet....thought I would check here first.
data:image/s3,"s3://crabby-images/3716e/3716ef23a44b7e17a6f9a534a7a0e99fbc25a2fa" alt="AWS to RGB Site Routing - half working.jpg"
data:image/s3,"s3://crabby-images/82ddf/82ddfbb37deb50bf863801c5d0da5ac135492170" alt="AWS to RGB Site Routing - half working.jpg_thumb" -
Once the tunnel is up it should be all about what you allow.. what do yor vpn firewall rules look like?
-
Here are my rules for the AWS (AWS) and Local Site (Site)
data:image/s3,"s3://crabby-images/e6a0f/e6a0f0c1c1d16655a968210fef3e9f5cc0b55118" alt="AWS FW.PNG"
data:image/s3,"s3://crabby-images/d0de5/d0de5a045afddef1017bfec4957e03154158981f" alt="AWS FW.PNG_thumb"
data:image/s3,"s3://crabby-images/304d8/304d8f7f69a89af5ac21656fa9792b6b4e081bbc" alt="AWS FW 2.PNG"
data:image/s3,"s3://crabby-images/f310e/f310e7ece2f6ec969012dc02aeef1a887d8255eb" alt="AWS FW 2.PNG_thumb"
data:image/s3,"s3://crabby-images/ef92a/ef92a7797148881d38a329fcda8691f41dd3aac9" alt="Site FW.PNG"
data:image/s3,"s3://crabby-images/ef1aa/ef1aaffadd0df5350dd7c93839c3aedac9b9b588" alt="Site FW.PNG_thumb"
data:image/s3,"s3://crabby-images/19f8d/19f8dd106abcabbf41e164f7afa0d45f2ac4b274" alt="Site FW 2.PNG"
data:image/s3,"s3://crabby-images/83076/830763da8b68069450ec6f3a8c540feb30609b98" alt="Site FW 2.PNG_thumb"
data:image/s3,"s3://crabby-images/9b272/9b2729d65161b0fc474ad74d1607dc7f187f9047" alt="Site FW 3.PNG"
data:image/s3,"s3://crabby-images/082dd/082dda0578bd46df5d15b6d315456fa36099434b" alt="Site FW 3.PNG_thumb" -
Just making a bump….
Just wondering if anyone has suggestions.
-
Added a Rule to allow all AWS to Remote…..now traffic works but now the issue has flipped....adding a rule to the Remote site has no impact/effect for traffic going the other way.
AWS to Remote now works.....before it didn't
Remote to AWS now FAILS.....before it worked.
All I added was a rule on the AWS Side for each remote site Example..... Allow all traffic source 172.31.0.0/16 destination 10.0.96.0/19
I am confused I tried adding a static route on the Remote site....(using the same above example) but it won't take the open VPN ip as a gateway (192.168.0.40.1), and using 10.0.96.1 does nothing.
Not sure if pushing a route via the OpenVPN connection would solve this.