Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Remote Client VPN can't traverse site-to-site VPN

    OpenVPN
    2
    3
    415
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      moikerz
      last edited by

      Hi all,
      I have two VPNs - a client-to-site VPN and a site-to-site VPN. When a client connects to Site1, they cannot access services at Site2. I don't believe I'm restricting anything. Firewall rules are open, I can see the states open but there's no response/connection.

      Example: remote client connects to Site 1 fine, accesses Site1 services fine. When attempting to ping or RDP to Site2, there's no response.

      Am I missing something common?

      Site1: 192.168.2.0
      Site2: 192.168.12.0
      OpenVPN client-to-site: 192.168.3.0
      OpenVPN site-to-site: 10.0.8.0

      A little confused...

      -Mike

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @moikerz
        last edited by

        @moikerz said in Remote Client VPN can't traverse site-to-site VPN:

        Am I missing something common?

        Maybe the routes. Hard to say, unless you provide more details about your vpn setup.

        To enable routing you have to add the site2 LAN network to the access server settings "Local Network/s".
        Additionally add the access servers tunnel network to the "Remote network/s" in the s2s settings on site2.

        M 1 Reply Last reply Reply Quote 1
        • M
          moikerz @viragomann
          last edited by

          @viragomann said in Remote Client VPN can't traverse site-to-site VPN:

          Additionally add the access servers tunnel network to the "Remote network/s" in the s2s settings on site2.

          That was it. Whoops. Adding 192.168.3.0/24 to Site2's site-to-site "Remote Networks" did the trick. Feeling a tad silly that I missed that .. multiple times. Appreciate the help!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.