Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Site to site VPN no traffic

    OpenVPN
    2
    7
    125
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      Daniel_Hyde last edited by

      Hi,

      I have setup a VPN from site A to site B.
      The main function of this is so site A can Access CCTV at site B and also use the WAN IP of site A to port forward as site B is on 4G.
      Anyone accessing the CCTV through the WAN IP of site A has no issues.
      If you try and access the CCTV from the LAN of site A no access, both Ping and Trace fail.
      If I Ping or Trace from pfSense at site A it works.
      Any ideas on how I can fix it?

      Thanks
      Dan

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @Daniel_Hyde last edited by

        @daniel_hyde
        Set the OpenVPN servers tunnel network mask to /30.

        Add the remote site's LAN into the "Remote Networks" box at both sites.

        D 1 Reply Last reply Reply Quote 0
        • D
          Daniel_Hyde @viragomann last edited by

          @viragomann

          I have done this already.

          Thanks
          Dan

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @Daniel_Hyde last edited by

            @daniel_hyde
            Also the /30 tunnel?
            With this and the correct remote networks settings at least ping from A LAN should work if it works from A pfSense.

            D 1 Reply Last reply Reply Quote 0
            • D
              Daniel_Hyde @viragomann last edited by

              @viragomann

              site A:
              90121330-a2d9-4e86-bb33-2eb1c2750c69-image.png

              site B:
              007fc1f7-e7a5-4a0c-b859-fd732a9b41e5-image.png

              Thanks
              Dan

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @Daniel_Hyde last edited by

                @daniel_hyde
                I see. So the routing should work.

                If you ping a device at site B from pfSense at A itself, the ping has the IP 10.3.100.1 (servers virtual IP) by default, when the packet arrive on the destination device, as long as you don't NAT it.
                So this source is outside from the site B LAN. Since the destination device accepts this, I would expect that it accepts a LAN IP of A as well.
                But maybe it is blocked by pfSense at site B? Are the rules configured accordingly?

                If so run a packets capture at B on OpenVPN and LAN, while you try to ping the device, to see what's going wrong.

                D 1 Reply Last reply Reply Quote 0
                • D
                  Daniel_Hyde @viragomann last edited by Daniel_Hyde

                  @viragomann

                  Please see firewall rules below from site B:

                  OpenVPN:
                  0e6387dd-1d86-458f-af8a-be16d6461f65-image.png

                  Tunnel Interface:
                  300f4805-9271-46a7-8ede-1601f50246e7-image.png

                  LAN:
                  044a0fd5-029b-48ac-af81-7eb97f75b868-image.png

                  Thanks
                  Dan

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post