Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    unable to ping between routers and from routers to LANs

    IPsec
    2
    8
    341
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      scarrrr last edited by scarrrr

      Hello, I made an ipsec tunnel with the wan interfaces in dhcp of the two routers. the two routers are in dhcp with a single internet box (I did not configure the ipsec tunnel with the public ip because I am at home).

      I can ping from pc and servers to routers but not vice versa on remote LANs and not between routers either.

      I created rules on all interfaces (WAN, LAN, IPSEC) but I still can't ping routers to remote LANs.projetsysteme.drawio.png tunnel1.PNG tunnel2.PNG

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @scarrrr last edited by

        @scarrrr
        Please, also show your phase 2 on both endpoints.
        I assume, both are the default gateways in their respective LAN.

        Did add firewall rules to allow the access?

        Also consider to configure the servers and computers firewall to allow access from the other network.

        S 1 Reply Last reply Reply Quote 0
        • S
          scarrrr @viragomann last edited by scarrrr

          @viragomann p2.PNG p2(2)..PNGipsecping.PNG ipsecsite1.PNG lansite1.PNG wansite1.PNG

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @scarrrr last edited by

            @scarrrr
            If you display the phase 2 IPSec status page, are they shown as connected?

            If so, I would expect that at least the ping from the router to the remote one to work. However, select the LAN as source, please and try again.

            S 1 Reply Last reply Reply Quote 0
            • S
              scarrrr @viragomann last edited by scarrrr

              @viragomann said in unable to ping between routers and from routers to LANs:

              @scarrrr
              If you display the phase 2 IPSec status page, are they shown as connected?
              If so, I would expect that at least the ping from the router to the remote one to work. However, select the LAN as source, please and try again.

              etat1.PNG etat2.PNGping.PNG

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @scarrrr last edited by

                @scarrrr
                Hit "show child SA entries". This shows the phase 2 state, I'm talking about.

                S 1 Reply Last reply Reply Quote 0
                • S
                  scarrrr @viragomann last edited by

                  @viragomann sous.PNG sous2.PNG

                  V 1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @scarrrr last edited by

                    @scarrrr
                    So both p2 seem to be up as well. No idea then, why you can't access the remote site.
                    Maybe are there different routes for the remote networks?

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post