<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenVPN: Factory01(client) &lt;-&gt; Factory02(server&#x2F;client) &lt;-&gt; Azure(server)]]></title><description><![CDATA[<p dir="auto">Hello!</p>
<p dir="auto">We currently use OpenVPN (site-to-site, on pfSense) between factories and Azure, with Azure being the main server for accessing systems.<br />
One of the factories recently, started to experience latency that has been causing a headache.</p>
<p dir="auto">Factory01(client) &lt;-100ms-&gt; Azure(server)<br />
Factory02(client) &lt;-170ms-&gt; Azure(server)</p>
<p dir="auto">Does anyone know if it is possible to perform the configuration below in OpenVPN, taking advantage of the low latency between factories and lower latency between Factory01 and Azure?<br />
10.10.3.0/24 &lt;-&gt; 10.10.2.0/24 &lt;-&gt; 10.10.1.0/24<br />
Factory02(client) &lt;-45ms-&gt; Factory01(server/client) &lt;-100ms-&gt; Azure(server)</p>
<p dir="auto">The idea would be to reach the 10.10.1.0/24 (Azure) on network 10.10.3.0/24 (Factory02) passing through 10.10.2.0/24 (Factory01).</p>
<p dir="auto">Thanks.</p>
]]></description><link>https://forum.netgate.com/topic/188085/openvpn-factory01-client-factory02-server-client-azure-server</link><generator>RSS for Node</generator><lastBuildDate>Thu, 05 Mar 2026 08:43:33 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/188085.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 09 May 2024 19:48:46 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to OpenVPN: Factory01(client) &lt;-&gt; Factory02(server&#x2F;client) &lt;-&gt; Azure(server) on Tue, 21 May 2024 14:29:05 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/rschossler">@<bdi>rschossler</bdi></a> said in <a href="/post/1168419">OpenVPN: Factory01(client) &lt;-&gt; Factory02(server/client) &lt;-&gt; Azure(server)</a>:</p>
<blockquote>
<p dir="auto">Factory02<br />
(Client OpenVPN Factory01): IPv4 Remote network(s): 10.10.2.0/24,10.10.1.0/24</p>
<p dir="auto">Factory01<br />
(Server OpenVPN Factory02): IPv4 Remote network(s): 10.10.3.0/24<br />
(Client OpenVPN Azure): IPv4 Remote network(s): 10.10.1.0/24</p>
<p dir="auto">Azure:<br />
(Server OpenVPN Factory01): IPv4 Remote network(s): 10.10.2.0/24,10.10.3.0/24</p>
</blockquote>
<p dir="auto">At first, I was carrying out a configuration with a test server, but the configuration did not work under any circumstances.<br />
Without success in the research, I carried out the configuration in the production environment and it worked.<br />
Even with the higher latency, OpenVPN communication from Factory02 through Factory01 was more stable with Azure.</p>
]]></description><link>https://forum.netgate.com/post/1170327</link><guid isPermaLink="true">https://forum.netgate.com/post/1170327</guid><dc:creator><![CDATA[rschossler]]></dc:creator><pubDate>Tue, 21 May 2024 14:29:05 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: Factory01(client) &lt;-&gt; Factory02(server&#x2F;client) &lt;-&gt; Azure(server) on Fri, 10 May 2024 13:37:10 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/rschossler">@<bdi>rschossler</bdi></a><br />
So I would expect the routes to work.</p>
<p dir="auto">If not, check in the routing tables of all involved nodes if the routes were added properly.</p>
<p dir="auto">If any is missing check the log for the reason.</p>
]]></description><link>https://forum.netgate.com/post/1168444</link><guid isPermaLink="true">https://forum.netgate.com/post/1168444</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Fri, 10 May 2024 13:37:10 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: Factory01(client) &lt;-&gt; Factory02(server&#x2F;client) &lt;-&gt; Azure(server) on Fri, 10 May 2024 12:26:31 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> said in <a href="/post/1168423">OpenVPN: Factory01(client) &lt;-&gt; Factory02(server/client) &lt;-&gt; Azure(server)</a>:</p>
<blockquote>
<p dir="auto">Azure:<br />
(Server OpenVPN Factory01): IPv4 Remote network(s): 10.10.1.0/24,10.10.2.0/24</p>
</blockquote>
<p dir="auto">Sorry, I just wrote it wrong.<br />
The correct thing would be:</p>
<p dir="auto">Azure:<br />
(Server OpenVPN Factory01): IPv4 Remote network(s): 10.10.2.0/24,10.10.3.0/24</p>
]]></description><link>https://forum.netgate.com/post/1168424</link><guid isPermaLink="true">https://forum.netgate.com/post/1168424</guid><dc:creator><![CDATA[rschossler]]></dc:creator><pubDate>Fri, 10 May 2024 12:26:31 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: Factory01(client) &lt;-&gt; Factory02(server&#x2F;client) &lt;-&gt; Azure(server) on Fri, 10 May 2024 12:22:21 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/rschossler">@<bdi>rschossler</bdi></a> said in <a href="/post/1168419">OpenVPN: Factory01(client) &lt;-&gt; Factory02(server/client) &lt;-&gt; Azure(server)</a>:</p>
<blockquote>
<p dir="auto">Azure:<br />
(Server OpenVPN Factory01): IPv4 Remote network(s): 10.10.1.0/24,10.10.2.0/24</p>
</blockquote>
<p dir="auto">The first one is local according to your above statements.</p>
]]></description><link>https://forum.netgate.com/post/1168423</link><guid isPermaLink="true">https://forum.netgate.com/post/1168423</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Fri, 10 May 2024 12:22:21 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: Factory01(client) &lt;-&gt; Factory02(server&#x2F;client) &lt;-&gt; Azure(server) on Fri, 10 May 2024 12:23:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> said in <a href="/post/1168414">OpenVPN: Factory01(client) &lt;-&gt; Factory02(server/client) &lt;-&gt; Azure(server)</a>:</p>
<blockquote>
<p dir="auto">So in the settings of Factory02(client) enter 10.10.1.0/24 into the "remote networks" box.</p>
<p dir="auto">And on Factory01 in the OpenVPN server settings, which Factory02 connects to enter 10.10.3.0/24 into the "remote networks" box.</p>
<p dir="auto">And on Azure you have to route both subnets to Factory01 now. So you have to enter "10.10.2.0/24,10.10.3.0/24" into the "remote networks" box.</p>
</blockquote>
<p dir="auto">This was the first test, without the <em>Custom options</em>.<br />
I believe that because the 10.10.1.0/24 network is available on the Azure server and not on Factory01, OpenVPN in Factory02 was unable to reach and create the route.</p>
<p dir="auto">First configuration:<br />
Factory02<br />
(Client OpenVPN Factory01): IPv4 Remote network(s): 10.10.2.0/24,10.10.1.0/24</p>
<p dir="auto">Factory01<br />
(Server OpenVPN Factory02): IPv4 Remote network(s): 10.10.3.0/24<br />
(Client OpenVPN Azure): IPv4 Remote network(s): 10.10.1.0/24</p>
<p dir="auto">Azure:<br />
(Server OpenVPN Factory01): IPv4 Remote network(s): 10.10.2.0/24,10.10.3.0/24</p>
]]></description><link>https://forum.netgate.com/post/1168419</link><guid isPermaLink="true">https://forum.netgate.com/post/1168419</guid><dc:creator><![CDATA[rschossler]]></dc:creator><pubDate>Fri, 10 May 2024 12:23:25 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: Factory01(client) &lt;-&gt; Factory02(server&#x2F;client) &lt;-&gt; Azure(server) on Fri, 10 May 2024 11:50:01 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/rschossler">@<bdi>rschossler</bdi></a><br />
There is no need to push routes to a client in a site to site setup. And even don't push or set routes in the custom options at all. pfSense provides the "Local Networks" and "Remote Networks" for this purpose.</p>
<p dir="auto">So in the settings of Factory02(client) enter 10.10.1.0/24 into the "remote networks" box.</p>
<p dir="auto">And on Factory01 in the OpenVPN server settings, which Factory02 connects to enter 10.10.3.0/24 into the "remote networks" box.</p>
<p dir="auto">And on Azure you have to route both subnets to Factory01 now. So you have to enter "10.10.2.0/24,10.10.3.0/24" into the "remote networks" box.</p>
]]></description><link>https://forum.netgate.com/post/1168414</link><guid isPermaLink="true">https://forum.netgate.com/post/1168414</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Fri, 10 May 2024 11:50:01 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: Factory01(client) &lt;-&gt; Factory02(server&#x2F;client) &lt;-&gt; Azure(server) on Fri, 10 May 2024 11:33:10 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> said in <a href="/post/1168326">OpenVPN: Factory01(client) &lt;-&gt; Factory02(server/client) &lt;-&gt; Azure(server)</a>:</p>
<blockquote>
<p dir="auto">Of course it's possible. It's just a thing of routes.</p>
</blockquote>
<p dir="auto">In the OpenVPN settings of Factory02, in <strong>IPv4 Remote network(s)</strong>, set <em>10.10.1.0/24,10.10.2.0/24</em>.<br />
In <strong>Custom options</strong>, entered <em>push "route 10.10.1.0/24 255.255.255.0"</em> but did not create the entry in the routing table (<strong>Diagnostics &gt; Routes</strong>).<br />
Again, in <strong>Custom options</strong>, enter <em>route 10.10.1.0 255.255.255.0 10.10.2.1</em>. This time the entry was created in the routing table, but without success in reaching 10.10.1.0/24.<br />
In <strong>Firewall &gt; Rules &gt; OpenVPN</strong>, a rule was created allowing IPv4*, without success.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> said in <a href="/post/1168326">OpenVPN: Factory01(client) &lt;-&gt; Factory02(server/client) &lt;-&gt; Azure(server)</a>:</p>
<blockquote>
<p dir="auto">But not sure if the latency would really be much better.</p>
</blockquote>
<p dir="auto">In a test carried out with the same internet link at Factory02 (OpenVPN Client from Factory01), forming the same circuit [Factory02(client) &lt;-&gt; Factory01(server/client) &lt;-&gt; Azure(server)], there really was no improvement.</p>
<p dir="auto"><img src="/assets/uploads/files/1715340781790-51fb5160-66c5-481f-9fe5-f95108effdc4-img01.png" alt="51fb5160-66c5-481f-9fe5-f95108effdc4-img01.png" class=" img-fluid img-markdown" /></p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> said in <a href="/post/1168326">OpenVPN: Factory01(client) &lt;-&gt; Factory02(server/client) &lt;-&gt; Azure(server)</a>:</p>
<blockquote>
<p dir="auto">Do you have the 45 ms between the factories over a VPN?</p>
</blockquote>
<p dir="auto">Yes, it has worked well.</p>
<p dir="auto"><img src="/assets/uploads/files/1715340059874-dc600db1-39f8-4f34-8e6d-3480cfabdd96-img02.png" alt="dc600db1-39f8-4f34-8e6d-3480cfabdd96-img02.png" class=" img-fluid img-markdown" /></p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> said in <a href="/post/1168326">OpenVPN: Factory01(client) &lt;-&gt; Factory02(server/client) &lt;-&gt; Azure(server)</a>:</p>
<blockquote>
<p dir="auto">Are there any packets losses between factory02 and Azure?</p>
</blockquote>
<p dir="auto">No packet loss.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> said in <a href="/post/1168326">OpenVPN: Factory01(client) &lt;-&gt; Factory02(server/client) &lt;-&gt; Azure(server)</a>:</p>
<blockquote>
<p dir="auto">I'd sniff the traffic to check if there is something wrong on the line, also the OpenVPN traffic on the WAN.</p>
</blockquote>
<p dir="auto">Recently we had meteorological problems that affected several communication services, but as there was no gain in the test carried out above, I will look for another alternative.</p>
<p dir="auto">Thanks.</p>
]]></description><link>https://forum.netgate.com/post/1168409</link><guid isPermaLink="true">https://forum.netgate.com/post/1168409</guid><dc:creator><![CDATA[rschossler]]></dc:creator><pubDate>Fri, 10 May 2024 11:33:10 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN: Factory01(client) &lt;-&gt; Factory02(server&#x2F;client) &lt;-&gt; Azure(server) on Thu, 09 May 2024 20:22:30 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/rschossler">@<bdi>rschossler</bdi></a><br />
Of course it's possible. It's just a thing of routes.<br />
But not sure if the latency would really be much better. Do you have the 45 ms between the factories over a VPN?</p>
<p dir="auto">Are there any packets losses between factory02 and Azure?<br />
I'd sniff the traffic to check if there is something wrong on the line, also the OpenVPN traffic on the WAN.</p>
]]></description><link>https://forum.netgate.com/post/1168326</link><guid isPermaLink="true">https://forum.netgate.com/post/1168326</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Thu, 09 May 2024 20:22:30 GMT</pubDate></item></channel></rss>