Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN (Site-to-Site) unable to ping/access from SiteA(Server) to SiteB(Client) LAN from Local Machine

    Scheduled Pinned Locked Moved OpenVPN
    15 Posts 4 Posters 1.4k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ Offline
      johnpoz LAYER 8 Global Moderator
      last edited by johnpoz

      How many devices do you have at each site, is it a handful then /24... If its 200+ then you might think of /23 if you think in the next few years you might grow to be larger then what a /24 can handle, ie 254

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

      P 1 Reply Last reply Reply Quote 0
      • P Offline
        PrashantRai @johnpoz
        last edited by

        @johnpoz for now it's around 150 machines, which is expected to grow in future...

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator
          last edited by

          well /24 gives you 254 Ips to work with... So that quite a bit of growth ;)

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

          P 2 Replies Last reply Reply Quote 1
          • P Offline
            PrashantRai @johnpoz
            last edited by

            @johnpoz well yeah..

            1 Reply Last reply Reply Quote 0
            • P Offline
              PrashantRai @johnpoz
              last edited by

              @johnpoz thanks man it worked.
              I was curious to know which all mask are overlapping, So I tested with some of the mask's, which are :

              1. SiteA - 10.10.1.X/8
                SiteB - 10.20.1.X/8 , testing didn't work out.

              2. SiteA - 10.10.1.X/8
                SiteB - 10.20.1.X/12 , testing didn't work out. It worked in only one direction

              3. SiteA - 10.10.1.X/12
                SiteB - 10.20.1.X/12 , testing worked. Both bi-direction ping/access is happening.

              4. SiteA - 10.10.1.X/12
                SiteB - 10.20.1.X/14 , testing worked. Both bi-direction ping/access is happening.

              Now if you don't mind can you please brief/explain why testing 1 and 2 failed, and also how to know if IP's are overlapping!!!!

              JKnottJ johnpozJ 2 Replies Last reply Reply Quote 0
              • RicoR Offline
                Rico LAYER 8 Rebel Alliance
                last edited by

                http://jodies.de/ipcalc โ˜บ

                -Rico

                P 1 Reply Last reply Reply Quote 1
                • P Offline
                  PrashantRai @Rico
                  last edited by

                  @Rico thank you ๐Ÿ™‚

                  1 Reply Last reply Reply Quote 0
                  • JKnottJ Offline
                    JKnott @PrashantRai
                    last edited by

                    @PrashantRai said in OpenVPN (Site-to-Site) unable to ping/access from SiteA(Server) to SiteB(Client) LAN from Local Machine:

                    Now if you don't mind can you please brief/explain why testing 1 and 2 failed, and also how to know if IP's are overlapping!!!!

                    In both, you actually have 10.0.0.0 /8. The other address in both examples is within that range. The /8 indicates 8 of the 32 bits are used for the network portion of the address and the other bits are for the device address. So, start with any address you wish and count the bits from the left. All the bits to that point are the network address and the rest are irrelevant. So, write out those network addresses first with all 0 to the right and again with all 1. This will show you the range of addresses that network would have.

                    PfSense running on Qotom mini PC
                    i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel 1 Gb Ethernet ports.
                    UniFi AC-Lite access point

                    I haven't lost my mind. It's around here...somewhere...

                    P 1 Reply Last reply Reply Quote 1
                    • P Offline
                      PrashantRai @JKnott
                      last edited by

                      @JKnott thank you ๐Ÿ™‚

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Offline
                        johnpoz LAYER 8 Global Moderator @PrashantRai
                        last edited by

                        @PrashantRai said in OpenVPN (Site-to-Site) unable to ping/access from SiteA(Server) to SiteB(Client) LAN from Local Machine:

                        also how to know if IP's are overlapping!!!!

                        You don't understand network masks, ie subnetting - but your setting up the firewall and site to site vpn? How is this?

                        So you rust randomly picking a mask? Where did you come up with the /12? I can understand the /8 somewhat since this is whole network for 10..

                        I would highly suggest you do a bit of research.
                        https://www.ittsystems.com/introduction-to-subnetting/

                        Came up on google like first hit, looks basic enough to get you started.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.