• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Multiple vti routed ipsec tunnels an issue?

Scheduled Pinned Locked Moved IPsec
9 Posts 2 Posters 854 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N
    nick.loenders
    last edited by Jun 15, 2023, 12:12 PM

    Hi,

    I have a Netgate at the Headquarters and multiple branch Netgates.
    Between the HQ and the branch offices there are standard ipsec tunnels.
    Between the HQ and one branch I made a vti routed ipsec tunnel.

    This all works.

    But now I need to change some standard ipsec tunnels to vti routed tunnels.

    So yesterday I disabled a tunnel between HQ and branch X and created a vti routed tunnel for that setup and suddenly the internet was lost on both locations.... :(

    Once I disabled the vti routed tunnel, internet was back.

    What can this have caused??

    M 1 Reply Last reply Jun 16, 2023, 2:32 PM Reply Quote 0
    • M
      michmoor LAYER 8 Rebel Alliance @nick.loenders
      last edited by Jun 16, 2023, 2:32 PM

      @nick-loenders How are your gateways set up.
      Default gateway should be your WAN interface
      See mine.

      8a4c999e-f799-4d82-a7fa-6ea4abaa7c18-image.png

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      N 1 Reply Last reply Jun 16, 2023, 2:43 PM Reply Quote 0
      • N
        nick.loenders @michmoor
        last edited by Jun 16, 2023, 2:43 PM

        @michmoor Hi, just back from that client.

        The WAN ip on the pfsense is 192.168.1 at the branch office and the local network at the main office is also 192.168.1

        that will probably have caused this...

        Allthough another branch office worked (or I thought it worked) and now from home again looking into it as I needed another P2 on the tunnel and poof gone again....

        All this because of the stupid Teams Voice they are using....

        M 2 Replies Last reply Jun 16, 2023, 2:45 PM Reply Quote 0
        • M
          michmoor LAYER 8 Rebel Alliance @nick.loenders
          last edited by Jun 16, 2023, 2:45 PM

          @nick-loenders The gateway sets to Automatic but when using VPNs and no Multi-WAN you have to make sure you set the default gateway otherwise you run the risk of the nexthop being the VPN which of course wont work if the Internet is down.

          Firewall: NetGate,Palo Alto-VM,Juniper SRX
          Routing: Juniper, Arista, Cisco
          Switching: Juniper, Arista, Cisco
          Wireless: Unifi, Aruba IAP
          JNCIP,CCNP Enterprise

          N 1 Reply Last reply Jun 16, 2023, 2:46 PM Reply Quote 0
          • N
            nick.loenders @michmoor
            last edited by Jun 16, 2023, 2:46 PM

            @michmoor Yes, but the default GW is set to the WAN gateway
            on both devices.

            1 Reply Last reply Reply Quote 0
            • M
              michmoor LAYER 8 Rebel Alliance @nick.loenders
              last edited by Jun 16, 2023, 2:47 PM

              @nick-loenders said in Multiple vti routed ipsec tunnels an issue?:

              The WAN ip on the pfsense is 192.168.1 at the branch office and the local network at the main office is also 192.168.1

              Can you explain this?
              Both sites have their LAN configured for 192.168.1.X ?

              Firewall: NetGate,Palo Alto-VM,Juniper SRX
              Routing: Juniper, Arista, Cisco
              Switching: Juniper, Arista, Cisco
              Wireless: Unifi, Aruba IAP
              JNCIP,CCNP Enterprise

              N 1 Reply Last reply Jun 16, 2023, 2:49 PM Reply Quote 0
              • N
                nick.loenders @michmoor
                last edited by Jun 16, 2023, 2:49 PM

                @michmoor the internal network (LAN) at HQ is 192.168.1

                The WAN ip at the branch get 192.168.1 from the ISP router/modem

                M 1 Reply Last reply Jun 16, 2023, 2:53 PM Reply Quote 0
                • M
                  michmoor LAYER 8 Rebel Alliance @nick.loenders
                  last edited by Jun 16, 2023, 2:53 PM

                  @nick-loenders Ok so branch is using CGNAT. But the CGNAT WAN has the same IP addr as your other site.
                  Yeah i can see how that may cause a routing problem at the branch but dont see how the Internet is lost at the HQ.....

                  Firewall: NetGate,Palo Alto-VM,Juniper SRX
                  Routing: Juniper, Arista, Cisco
                  Switching: Juniper, Arista, Cisco
                  Wireless: Unifi, Aruba IAP
                  JNCIP,CCNP Enterprise

                  N 1 Reply Last reply Jun 16, 2023, 2:58 PM Reply Quote 0
                  • N
                    nick.loenders @michmoor
                    last edited by Jun 16, 2023, 2:58 PM

                    @michmoor Yeah, we'll ask to change that iprange

                    But indeed when working remote, this looses internet, also at the HQ.

                    When I was trying at the HQ locally this morning, it did not get lost.... so weird

                    And just now on the branch it did seem to work when I left I came home and added a second P2 to the tunnel (and somehow I also saw the ipsec gateway was down in a glitch) it went down again....

                    it does not like me when I try to do thing from home apparently

                    When the local IT guy disabled the ipsec tunnel, internet was working again

                    1 Reply Last reply Reply Quote 0
                    9 out of 9
                    • First post
                      9/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received