• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Bye Pass traffic with two different P2P tunnel using Open VPN

Scheduled Pinned Locked Moved OpenVPN
6 Posts 2 Posters 985 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G
    Gokulapandi
    last edited by Apr 21, 2023, 5:57 AM

    We have 3 offices in different locations, we have a peer to peer tunnel between office A & B and We have another Peer to peer tunnel between Office B & C. We can communicate between Office A LAN to Office B LAN, also can communicate between Office B LAN to Office C LAN.

    Here we want to establish connection from Office C LAN to Office A LAN via peer to peer tunnel office B & C and peer to peer tunnel office B & A (10.1.5.0/24 → 10.1.4.0/24 → 10.1.2.0/24 → 10.1.1.0/24). Can anyone help me with this ?

    29ed6bb5-38db-4ceb-879e-16f3c79a5860-image.png

    V 1 Reply Last reply Apr 21, 2023, 12:23 PM Reply Quote 0
    • V
      viragomann @Gokulapandi
      last edited by Apr 21, 2023, 12:23 PM

      @gokulapandi
      You simply have to add the respective remote subnet to the "Remote Networks" in the OpenVPN settings at A and C.

      So at A you will have then:

      10.1.3.0/24,10.1.5.0/24
      

      and at C:

      10.1.3.0/24,10.1.1.0/24
      

      Also ensure that the firewall rules on all involved incoming interfaces allow the access.

      1 Reply Last reply Reply Quote 1
      • G
        Gokulapandi
        last edited by Gokulapandi Apr 21, 2023, 1:10 PM Apr 21, 2023, 1:10 PM

        Hi viragomann,

        Thanks for your response, As you mentioned, i have already added the remote network at A & C.

        At A, I Have allowed inbound/outbound for 10.1.5.0/24, 10.1.4.0/24, 10.1.3.0/24 Network to LAN Network in LAN Rule and Open VPN rule.

        At C, I have allowed inbound/outbound for 10.1.1.0/24, 10.1.2.0/24, 10.1.3.0/24 Network to LAN Network in LAN Rule and Open VPN Rule.

        At B, I have allowed inbound/outbound for 10.1.1.0/24 and 10.1.5.0/24 Network to other Network (10.1.2.0/24, 10.1.4.0/24, 10.1.3.0/24) in ** only Open VPN Rule.**

        I have configured and tried all the combination firewall rule as above mentioned but still not working.

        V 1 Reply Last reply Apr 21, 2023, 1:22 PM Reply Quote 0
        • V
          viragomann @Gokulapandi
          last edited by Apr 21, 2023, 1:22 PM

          @gokulapandi said in Bye Pass traffic with two different P2P tunnel using Open VPN:

          At A, I Have allowed inbound/outbound for 10.1.5.0/24, 10.1.4.0/24, 10.1.3.0/24 Network to LAN Network in LAN Rule and Open VPN rule.
          At C, I have allowed inbound/outbound for 10.1.1.0/24, 10.1.2.0/24, 10.1.3.0/24 Network to LAN Network in LAN Rule and Open VPN Rule.

          Rules need only to be added to the incoming interfaces, i.e. the VPN interfaces.

          The tunnel networks are not needed to pass, as long as you do not masquerade the traffic with an outbound NAT rule on the VPN interface.

          At B, I have allowed inbound/outbound for 10.1.1.0/24 and 10.1.5.0/24 Network to other Network (10.1.2.0/24, 10.1.4.0/24, 10.1.3.0/24) in ** only Open VPN Rule.**

          If you have stated the destination networks, you need 10.1.1.0/24 and 10.1.5.0/24 here.

          G 1 Reply Last reply May 5, 2023, 5:54 AM Reply Quote 0
          • G
            Gokulapandi @viragomann
            last edited by May 5, 2023, 5:54 AM

            Hi viragomann,

            Will this work ?

            a14e2a87-85f7-4875-a163-2660a2e68dec-image.png

            V 1 Reply Last reply May 5, 2023, 2:43 PM Reply Quote 0
            • V
              viragomann @Gokulapandi
              last edited by May 5, 2023, 2:43 PM

              @gokulapandi
              Yes should work for A and C.
              But if you restrict access on B to certain subnets as well, you need to add the same rule as you have at A on the interface connected C and that one you have at C on the interface connected to A.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received