<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Can&#x27;t Get The Gateway up for a Site-To-Site OpenVPN  Connection.]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">Perhaps someone can spot my error, I've removed my RAS and Client from two pfSense connections and am trying to replace the connection with a Site-to-Site connection, using the same subnets. My target looks like this:</p>
<p dir="auto"><img src="/assets/uploads/files/1656324544170-site2site.drawio.png" alt="Site2Site.drawio.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">My goal is to connect the two sites over the two vlans. My CA structure is in place and working.</p>
<p dir="auto">I’ve basically followed the pfsense setup for 2 sites</p>
<p dir="auto">https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-s2s-tls.html</p>
<p dir="auto">I’ve setup my CA and certs, I believe it works as it should.</p>
<p dir="auto">My vpn server setup looks like this:</p>
<p dir="auto"><img src="/assets/uploads/files/1656324898946-001.png" alt="001.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">My Create Client-Specific Overrides look like this:</p>
<p dir="auto"><img src="/assets/uploads/files/1656324933938-002.png" alt="002.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">My WAN rule looks like this:</p>
<p dir="auto"><img src="/assets/uploads/files/1656324960797-003.png" alt="003.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">I’ve created an interface:</p>
<p dir="auto"><img src="/assets/uploads/files/1656324986465-004.png" alt="004.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">My firewall rules for the interface look like this, in the alias all subnets I use are included:</p>
<p dir="auto"><img src="/assets/uploads/files/1656325014301-005.png" alt="005.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">My outbound NAT rule:</p>
<p dir="auto"><img src="/assets/uploads/files/1656325288572-007.png" alt="007.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">At this stage on the Server side I believe that gateway should be up, before even looking at the client but still not up.</p>
<p dir="auto">Can’t quite tell if the route is setup correctly:<br />
<img src="/assets/uploads/files/1656325041367-006.png" alt="006.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">I have setup the client side also and it appears that there is a connection of sorts:</p>
<p dir="auto"><img src="/assets/uploads/files/1656325152808-008.png" alt="008.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Any clues on what I’ve messed up I just can’t see it …</p>
]]></description><link>https://forum.netgate.com/topic/173032/can-t-get-the-gateway-up-for-a-site-to-site-openvpn-connection</link><generator>RSS for Node</generator><lastBuildDate>Tue, 19 May 2026 12:22:54 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/173032.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 27 Jun 2022 10:19:40 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Can&#x27;t Get The Gateway up for a Site-To-Site OpenVPN  Connection. on Mon, 27 Jun 2022 12:48:59 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> actually I use an alias with my various subnets, including the tunnel subnets, so I believe it is covered. I also use an interface for my OpenVPN servers and don't use the "general" OpenVPN tab as such. That way I have some idea what is going on by doing things manually.</p>
<p dir="auto">I need to do a bit more digging into this.</p>
]]></description><link>https://forum.netgate.com/post/1048305</link><guid isPermaLink="true">https://forum.netgate.com/post/1048305</guid><dc:creator><![CDATA[neogrid]]></dc:creator><pubDate>Mon, 27 Jun 2022 12:48:59 GMT</pubDate></item><item><title><![CDATA[Reply to Can&#x27;t Get The Gateway up for a Site-To-Site OpenVPN  Connection. on Mon, 27 Jun 2022 12:39:31 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/neogrid">@<bdi>neogrid</bdi></a><br />
Checked you screens again. The only one failure I can find is the source network in the firewall rule on PEMSITE_A. The pass rules only allows access for the tunnel network, but not the clients LAN.</p>
<p dir="auto">However, this is also applied now when using a /30 tunnel.<br />
But maybe there are rules on the OpenVPN tab allowing access to any source.</p>
<p dir="auto">Remember that the OpenVPN tab is an interface group which includes all OpenVPN instances you're running on this node. Rule on interface groups have priority over ones on the interface tab. So if there is a rule for allowing any to any (default after running the OpenVPN server setup wizard), rules on the interface tabs are ignored.</p>
]]></description><link>https://forum.netgate.com/post/1048301</link><guid isPermaLink="true">https://forum.netgate.com/post/1048301</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Mon, 27 Jun 2022 12:39:31 GMT</pubDate></item><item><title><![CDATA[Reply to Can&#x27;t Get The Gateway up for a Site-To-Site OpenVPN  Connection. on Mon, 27 Jun 2022 12:24:43 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> ok thanks very much for the help.  I must have made a config error, though I'm sure I triple checked everything. I'll look into the CSO a bit more. Thanks for helping out.</p>
]]></description><link>https://forum.netgate.com/post/1048295</link><guid isPermaLink="true">https://forum.netgate.com/post/1048295</guid><dc:creator><![CDATA[neogrid]]></dc:creator><pubDate>Mon, 27 Jun 2022 12:24:43 GMT</pubDate></item><item><title><![CDATA[Reply to Can&#x27;t Get The Gateway up for a Site-To-Site OpenVPN  Connection. on Mon, 27 Jun 2022 12:18:47 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/neogrid">@<bdi>neogrid</bdi></a><br />
As mentioned, when you use a larger tunnel network, you need a CSO and the configuration gets more complicated.</p>
<p dir="auto">The CSO is especially needed at server site to route the clients site LAN properly.<br />
If that doesn't work check in the OpenVPN log if the CSO is applied. There are often issues due to wrong common names stated in the CSO or whatever.</p>
]]></description><link>https://forum.netgate.com/post/1048292</link><guid isPermaLink="true">https://forum.netgate.com/post/1048292</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Mon, 27 Jun 2022 12:18:47 GMT</pubDate></item><item><title><![CDATA[Reply to Can&#x27;t Get The Gateway up for a Site-To-Site OpenVPN  Connection. on Mon, 27 Jun 2022 11:48:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> What witchcraft is this ??</p>
<p dir="auto">Clearly I don't understand something, though I know not what.</p>
<p dir="auto">Why when I change my tunnel IP from 192.168.140.0/24 to 10.128.240.0/30 (disabling the CSO) does it now work ?</p>
<p dir="auto">I thought the main principle was that there should be no overlapping IP ranges (I had tried a different /24 subnet I had never used and it did not work either).</p>
]]></description><link>https://forum.netgate.com/post/1048284</link><guid isPermaLink="true">https://forum.netgate.com/post/1048284</guid><dc:creator><![CDATA[neogrid]]></dc:creator><pubDate>Mon, 27 Jun 2022 11:48:42 GMT</pubDate></item><item><title><![CDATA[Reply to Can&#x27;t Get The Gateway up for a Site-To-Site OpenVPN  Connection. on Mon, 27 Jun 2022 10:56:20 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/neogrid">@<bdi>neogrid</bdi></a><br />
So instead of CSO enter the server sides LAN into the "Remote Networks" box in the client settings.</p>
]]></description><link>https://forum.netgate.com/post/1048271</link><guid isPermaLink="true">https://forum.netgate.com/post/1048271</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Mon, 27 Jun 2022 10:56:20 GMT</pubDate></item><item><title><![CDATA[Reply to Can&#x27;t Get The Gateway up for a Site-To-Site OpenVPN  Connection. on Mon, 27 Jun 2022 10:51:01 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> It's a single pfSense box. Let me try it.</p>
]]></description><link>https://forum.netgate.com/post/1048270</link><guid isPermaLink="true">https://forum.netgate.com/post/1048270</guid><dc:creator><![CDATA[neogrid]]></dc:creator><pubDate>Mon, 27 Jun 2022 10:51:01 GMT</pubDate></item><item><title><![CDATA[Reply to Can&#x27;t Get The Gateway up for a Site-To-Site OpenVPN  Connection. on Mon, 27 Jun 2022 10:48:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/neogrid">@<bdi>neogrid</bdi></a><br />
The question is how many OpenVPN clients are connecting to the server. The devices behind the client don't matter at all.</p>
<p dir="auto">If you have only one OpenVPN client use a /30 tunnel and remove the CSO.<br />
If you have multiple clients you need a CSO for each.</p>
]]></description><link>https://forum.netgate.com/post/1048268</link><guid isPermaLink="true">https://forum.netgate.com/post/1048268</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Mon, 27 Jun 2022 10:48:23 GMT</pubDate></item><item><title><![CDATA[Reply to Can&#x27;t Get The Gateway up for a Site-To-Site OpenVPN  Connection. on Mon, 27 Jun 2022 10:44:46 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a>  hi</p>
<p dir="auto">On the client side there will be multiple machines but I won't run out IP addresses.</p>
<p dir="auto">However, I thought this configuration / approach should work.</p>
<p dir="auto">Is the error the CSO ? It looked ok to me.</p>
]]></description><link>https://forum.netgate.com/post/1048267</link><guid isPermaLink="true">https://forum.netgate.com/post/1048267</guid><dc:creator><![CDATA[neogrid]]></dc:creator><pubDate>Mon, 27 Jun 2022 10:44:46 GMT</pubDate></item><item><title><![CDATA[Reply to Can&#x27;t Get The Gateway up for a Site-To-Site OpenVPN  Connection. on Mon, 27 Jun 2022 10:34:41 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/neogrid">@<bdi>neogrid</bdi></a><br />
Is there only a single client connecting to the server or multiple?<br />
If it's only one you should rather use a /30 tunnel network for a site-to-site VPN. So there is no need to configure a CSO.</p>
]]></description><link>https://forum.netgate.com/post/1048265</link><guid isPermaLink="true">https://forum.netgate.com/post/1048265</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Mon, 27 Jun 2022 10:34:41 GMT</pubDate></item></channel></rss>