Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    problem for routing specific traffic through gre ipsec tunnel

    Scheduled Pinned Locked Moved NAT
    24 Posts 2 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      vistatech
      last edited by

      1- no it can't ping x.x.x.193. should i route the requests for that??

      0_1548156687710_Capture3.PNG

      K 1 Reply Last reply Reply Quote 0
      • K
        Konstanti @vistatech
        last edited by

        @vistatech
        Show packet capture on the lan interface

        1 Reply Last reply Reply Quote 0
        • V
          vistatech
          last edited by

          it is similar to pinging 10.1.1.150 just request and no reply

          K 1 Reply Last reply Reply Quote 0
          • K
            Konstanti @vistatech
            last edited by

            @vistatech
            here you can see that the answer comes to the gre interface
            and on the lan interface the answer comes ?

            0_1548158705927_20f3f461-82b6-4c82-83fc-4c3b423de55e-image.png

            1 Reply Last reply Reply Quote 0
            • V
              vistatech
              last edited by vistatech

              no. it does not come to lan interface. here is what i assumed:
              that capture is when i ping 10.1.1.150 (remote GRE ip) from my windows box (192.168.10.4) packet capture on lan shows a bunch of request. but packet capture on gre shows that requests from 192.168.251.194 (my side of GRE) goes to 10.1.1.150 and reply comes from 10.1.1.150 to x.x.x.194 and from there it does not come to my windows box.

              K 1 Reply Last reply Reply Quote 0
              • K
                Konstanti @vistatech
                last edited by

                @vistatech
                Are there any Floating Rules ?

                1 Reply Last reply Reply Quote 0
                • V
                  vistatech
                  last edited by vistatech

                  yes there is one, for GRE interface, with source and destination set to any.
                  since the requests go through 192.168.251.194, it seems like routing is being done, but NAT is not.

                  K 1 Reply Last reply Reply Quote 0
                  • V
                    vistatech
                    last edited by

                    should i be able to ping my local windows host (192.168.10.4) from my GRE interface?? if yes i can't.

                    1 Reply Last reply Reply Quote 0
                    • K
                      Konstanti @vistatech
                      last edited by

                      @vistatech
                      Show this rule

                      1 Reply Last reply Reply Quote 0
                      • V
                        vistatech
                        last edited by

                        which rule?

                        K 1 Reply Last reply Reply Quote 0
                        • K
                          Konstanti @vistatech
                          last edited by

                          @vistatech said in problem for routing specific traffic through gre ipsec tunnel:

                          which rule

                          Floating rule for GRE interface

                          And still such question
                          GRE over ipsec
                          ipsec (phase 2) in transport mode ?
                          is this correct ?
                          It's just that Pfsense doesn't always work correctly with GRE over ipsec.

                          1 Reply Last reply Reply Quote 0
                          • V
                            vistatech
                            last edited by

                            0_1548223589360_Capture.PNG

                            yes, ipsec phase 2 is in transport mode.

                            K 1 Reply Last reply Reply Quote 0
                            • K
                              Konstanti @vistatech
                              last edited by Konstanti

                              @vistatech
                              Hey
                              As I said , PF does not always work correctly with GRE over IPSEC.
                              Try to do so

                              1. disable GRE interface
                              2. reboot
                              3. Verify that THE IPSec tunnel is established
                              4. enable the GRE interface
                                5.verify
                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.