Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Tunnel VPN not working without CSO?!?!?!

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 2 Posters 779 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      M0L50N
      last edited by

      Hi community,

      I'm missing something ... not the first time I mount a P2P VPN between two pfsense. On one Tunnel, I have to add a CSO on the server to be able ping one network to another. If I disable the CSO, unable to ping remote network from server side and vice-versa.

      The only setting in the CSO is the IPv4 Remote Network/s, with that everything working like a charm!!!!

      ANyone have an idea??? My setup is basic but I miss something ... I'm not supposed to be obligated to ADD a Client Specific Override for a simple P2P tunnel between 2 sites ?!?!?

      Thanks for any sugggestion ... that's not a big deal but I'm curious.

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @M0L50N
        last edited by

        @m0l50n
        Hi,

        if it is a real Peer to peer it doesn't need a CSO.
        In a P2P you have only two peers, server and client. So for what reason would you need a CSO?

        Note that a P2P tunnel should have a /30 mask.

        M 1 Reply Last reply Reply Quote 1
        • M
          M0L50N @viragomann
          last edited by

          @viragomann You got it ... I was on a /24 mask!!! I copy my config from my other tunnel but this one is a tunnel with multi sites! By the way, for that tunnel, is it better to have the smallest mask as possible or /24 is ok?

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @M0L50N
            last edited by

            @m0l50n
            No, for an access server it's ok to have a /24 mask.

            M 1 Reply Last reply Reply Quote 1
            • M
              M0L50N @viragomann
              last edited by

              @viragomann Thanks again for you always clear and relevant answers!

              Have a good day!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.