<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Site2Site VPN debugging]]></title><description><![CDATA[<p dir="auto">I've setup a site2site vpn.<br />
It connects fine.<br />
The routes show on both (PFSense) firewalls fine.<br />
From the LAN either side (or firewall to other LAN) I cannot ping on the other side.<br />
traceroute doesn't show anything.<br />
I've even tries any/any rules to the LAN and openvpn on both sides.<br />
I have remote connection vpns working fine, to both firewalls.<br />
The only thing left is using a remote connection and manually adding nat's and routes.<br />
Not something I want to do really, but I'm at a loss.</p>
<p dir="auto">I've checked the docs and it matches up OK.<br />
This is SG-1000 (2.4) to 2.3.x</p>
]]></description><link>https://forum.netgate.com/topic/115855/site2site-vpn-debugging</link><generator>RSS for Node</generator><lastBuildDate>Mon, 14 Sep 2026 20:55:02 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/115855.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 18 May 2017 17:46:21 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Site2Site VPN debugging on Fri, 19 May 2017 19:39:14 GMT]]></title><description><![CDATA[<p dir="auto">Unfortunately it's not client firewalls either, I checked that.<br />
I can only think it's broken for me (or me that's broken!).<br />
I'm going to see if IPSEC works any better, or helps me diagnose the problem, but that's not looking good at the moment either.<br />
That's saying auth failed, when the pre-shared secret is definitely identical.<br />
I'm missing something obvious and daft clearly!<br />
Trawl the internet and docs read and re-read I guess.</p>
<p dir="auto">No Idea what is going on with openvpn and site-to-site, but I got IPSec working fairly quickly.<br />
So I'm happier with IPSec for site-to-site anyway - I can only think there is something broken with openvpn site to site with my setup somehow.</p>
]]></description><link>https://forum.netgate.com/post/700698</link><guid isPermaLink="true">https://forum.netgate.com/post/700698</guid><dc:creator><![CDATA[deadmalc]]></dc:creator><pubDate>Fri, 19 May 2017 19:39:14 GMT</pubDate></item><item><title><![CDATA[Reply to Site2Site VPN debugging on Thu, 18 May 2017 21:49:00 GMT]]></title><description><![CDATA[<p dir="auto">Check if the computers firewalls blocks the access from the other site.</p>
<p dir="auto">For debugging you may use Diagnostics &gt; Packet Capture.<br />
For instance, take a capture on LAN interface with ICMP filter while you try a ping from the other side to a LAN device. Check if you see the packets here and if responses come back from the destination device.</p>
]]></description><link>https://forum.netgate.com/post/700534</link><guid isPermaLink="true">https://forum.netgate.com/post/700534</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Thu, 18 May 2017 21:49:00 GMT</pubDate></item></channel></rss>