Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Roadwarriors @ Branch1 cannot see range on other side of IPSec tunnel @ Branch2

    OpenVPN
    1
    1
    329
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      Fluxosaurus last edited by

      Hi, somewhat of a n00b here, love pfSense!

      I have two remote branches connected for file sharing by two pfSense boxes.
      Both sites are version 2.2.6 (I know there is an update, but that will temporarily break my Lightsquid, and I have this problem so holding off for now.)
      We used IPSec with a PSK to create the tunnel between the branches.
      Then we used OpenVPN section to create a server for Roadwarriors to connect when away from branches.

      Server is in Remote Access SSl/TLS + User Auth mode.
      UDP – 1194
      Server certificate in use (using the pfSense box to create that certificate)

      Site 1 – range 192.168.11.0/24

      Site 2 – range 192.168.3.0/24

      When a user is at either branch, they can see either server through the tunnel. (The tunnel works)

      However when an OpenVPN roadwarrior (outside of a branch) connects to site 1, she can see the server on the 192.168.11.0 range perfectly.
      But she cannot see the server on the 192.168.3.0 range at all. I cannot ping anything in that range when connected to Site 1.

      Things I have tried:

      a. In my OpenVPN Server configuration I have added under Tunnel Settings – IPV4 Local Networks
      192.168.11.0/24, 192.168.3.0/24

      b. In my OpenVPN Server configuration I have added under Advanced Configuration – Advanced
      push "route 192.168.3.0 255.255.255.0"

      None of that worked.

      Is there a way to route traffic from an OpenVPN connected user, through the IPSec tunnel to the 192.168.3.0 range when connected to site 1 (and I’m assuming I can replicate this if a roadwarrior connects to Site 2 using OpenVPN and wants to see the server on the 192.168.11.0 range on the other side of the IPSec tunnel.)?

      Live long and Prosper

      1 Reply Last reply Reply Quote 0
      • First post
        Last post

      Products

      • Platform Overview
      • TNSR
      • pfSense
      • Appliances

      Services

      • Training
      • Professional Services

      Support

      • Subscription Plans
      • Contact Support
      • Product Lifecycle
      • Documentation

      News

      • Media Coverage
      • Press
      • Events

      Resources

      • Blog
      • FAQ
      • Find a Partner
      • Resource Library
      • Security Information

      Company

      • About Us
      • Careers
      • Partners
      • Contact Us
      • Legal
      Our Mission

      We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

      Subscribe to our Newsletter

      Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

      © 2021 Rubicon Communications, LLC | Privacy Policy