Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Route traffic through multiple site2site VPNs

    Scheduled Pinned Locked Moved OpenVPN
    3 Posts 2 Posters 753 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      Juffi
      last edited by

      Hello!

      I have 2 sites (192.168.33.1, 192.168.44.1) which are connected through a OpenVPN Site2Site VPN.

      Clients from Site1 (192.168.33.1) can reach server 10.0.10.10 through IPsec Site2Site
      Firewall of Site2 (192.168.44.1) can ping server 10.0.10.10
      Clients of Site2 can´t ping server 10.0.10.10

      Network plan:

      network-plan.png

      Firewall Rules 192.168.44.1: Lan and Openvpn: everything allowed

      So why can the firewall ping the server but not the clients behind the firewall? What have I forgotten?

      Thanks a lot!

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @Juffi
        last edited by

        @juffi
        Did you configure the VPN routing properly?

        You have to add an additional IPSec phase 2 for the network at site 2 and that one behind the IPSec.
        So at site 1:
        local: 192.168.44.0/24
        remote: 10.0.10.0/24
        and at the other site the other way around.

        And at site 2 you have to add the remote network behind the IPSec 10.0.10.0/24 to the "Remote Networks" in the OpenVPN config to route traffic to site 1.

        J 1 Reply Last reply Reply Quote 1
        • J
          Juffi @viragomann
          last edited by

          @viragomann Thanks a lot! For the IPSec tunnel i configured the opvenvpn tunnel network address and not the local network of the site (192.168.44.1).
          Thanks a lot!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.