• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Can ping routers but NOT computers on IPSec tunnel remote sites

Scheduled Pinned Locked Moved IPsec
7 Posts 5 Posters 5.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    saffo
    last edited by Jan 8, 2012, 10:18 PM

    Hi,
    I have site-to-site IPSec tunnel configured and established between two v2.0.1 pfsense routers. I can ping from one router to another one on remote site on LAN address vice versa. I can ping and access router A on remote site B computer. Also I can ping and access router B from remote computer on site A.

    But I cant access anything behind this two router. I cant ping or access server on site A from computer od site B, or access server on B site from computer on A site. A can access only routers.

    I tried everything I think, please help me ! Thank you.

    1 Reply Last reply Reply Quote 0
    • C
      cmb
      last edited by Jan 9, 2012, 2:24 AM

      sounds like your return routing isn't valid, default gateway not pointing back to the LAN IP on each side.

      1 Reply Last reply Reply Quote 0
      • M
        mrdoctor
        last edited by Jan 9, 2012, 2:52 AM

        Do you check your firewall rule?  ;)

        1 Reply Last reply Reply Quote 0
        • S
          saffo
          last edited by Jan 9, 2012, 9:08 AM

          @cmb:

          sounds like your return routing isn't valid, default gateway not pointing back to the LAN IP on each side.

          Yes problem should be there, but I do not understand how and where set this "pointing back to the LAN IP". I think I have everything configured correctly, but probably not :) . Can you describe it wider please? I not IT newbie but in pfsense IPSec case I feel like lama.
          Many thanks !

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by Jan 9, 2012, 9:42 AM

            The default gateway on hosts on both sides of the network must point to pfsense, or alternatively you'll need a static route on the device that is the default gateway.

            1 Reply Last reply Reply Quote 0
            • C
              craigduff
              last edited by Jan 17, 2012, 4:55 PM

              Make sure also on both sides of the networks under rules and then IPsec tab to config to allow access. Me personally on both sides i allow any lan triffic to pass through on both sides. So for me i have stars * on all the options.

              Kind Regards,
              Craig

              1 Reply Last reply Reply Quote 0
              • B
                blake.hunter
                last edited by Jan 22, 2012, 2:26 AM

                Try disabling the firewall on the computers. Even though you cannot ping them, can yopu remote desktop to them? I found that windows 7 and XP can nativly block ping replies, especially from different subnets. Turn windows firewall of and then try to ping. You can create an exception in windows firewall to reply if you decide you want to leave it on.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  [[user:consent.lead]]
                  [[user:consent.not_received]]