<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[strange openvpn ipsec routing problem]]></title><description><![CDATA[<p dir="auto">i have 2 pfsense boxes conected via ipsec, i want to enable openvpn in both of them with the clients having the ability to conect to remote ipsec network so i do the following setup</p>
<p dir="auto">pfsense 1<br />
Lan network 10.10.10.0/24<br />
LanIP 10.10.10.1<br />
OVPN Network 10.10.30.0/27<br />
OVPN server  10.10.30.1<br />
IPsec p2 entries<br />
LAN  			&lt;-&gt; 10.10.20.0/24  (lan to remote lan)<br />
10.10.30.0/27 	&lt;-&gt; 10.10.20.0/24  (opvn to remote lan)<br />
LAN  			&lt;-&gt; 10.10.30.32/27 (remoteovpn to lan)<br />
Firewall<br />
ovpn rule<br />
any to any<br />
Ipsec rules<br />
10.10.20.0/24<br />
10.10.30.0/24 (opvn local and remote)</p>
<p dir="auto">pfsense 2<br />
Lan network 10.10.20.0/24<br />
LanIP 10.10.20.1<br />
OVPN Network 10.10.30.32/27	<br />
OVPN server  10.10.30.33<br />
IPsec p2 entries<br />
LAN  			&lt;-&gt; 10.10.10.0/24  (lan to remote lan)<br />
10.10.30.32/27 	&lt;-&gt; 10.10.10.0/24  (opvn to remote lan)<br />
LAN  			&lt;-&gt; 10.10.30.0/27 (remoteovpn to lan)<br />
Firewall<br />
ovpn rule<br />
any to any<br />
Ipsec rules<br />
10.10.10.0/24<br />
10.10.30.0/24 (opvn local and remote)</p>
<p dir="auto">When i conenect to openvpn network in pfsense box 1 (10.10.30.2) i can ping to any host in the box 2 network (10.10.20.0/24), so far so god.<br />
But when i connect to openvpn network in pfsense box 2 (10.10.30.34) i can't ping to any host in the box 1 network (10.10.10.0/24)<br />
When i see the states in box2 it seems pfsense it's not routing the traffic coming from the openvpn server correctly</p>
<p dir="auto">Interface 	Protocol  	Source 														State 	Packets 	Bytes 	<br />
ovpns1 		icmp 		10.10.30.34:1 -&gt; 10.10.10.5:1 								0:0 	4 / 0 		240 B / 0 B 	<br />
WAN 		icmp 		xxx.xxx.xxx.xxx:9289 (192.168.10.34:1) -&gt; 10.10.10.5:9289 	0:0 	4 / 0 		240 B / 0 B</p>
<p dir="auto">Any ideas?</p>
]]></description><link>https://forum.netgate.com/topic/140633/strange-openvpn-ipsec-routing-problem</link><generator>RSS for Node</generator><lastBuildDate>Sat, 16 May 2026 01:52:45 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/140633.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 15 Feb 2019 16:52:51 GMT</pubDate><ttl>60</ttl></channel></rss>