Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Slave not reachable through ipsec tunnel

    IPsec
    2
    3
    1782
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cartman987 last edited by

      Hi all,

      I have the following setup:

      WAN(/24): 10.0.0.1 (VIP)
      10.0.0.2 Master
      10.0.0.3 Slave

      LAN(/24): 192.168.0.1 (VIP)
      192.168.0.2 Master
      192.168.0.3 Slave

      The Tunnel is up and running IPSEC is using the wan vip interface. Ping from the remote network (192.168.1.0/24) to the vip and master LAN address is working, ping to slave is timing out. Any ideas?

      Regards,
      cartman

      1 Reply Last reply Reply Quote 0
      • jimp
        jimp Rebel Alliance Developer Netgate last edited by

        That is normal/expected.

        The slave believes it has a better path back via its own tunnel, even though it is down.

        To fix it, you'll need to be on manual outbound NAT and add a rule so it does NAT on the traffic from the VPN subnet going to the slave's IP, and vice versa. that way it appears to originate from the opposing firewall and not the VPN, so the traffic returns as expected.

        1 Reply Last reply Reply Quote 0
        • C
          cartman987 last edited by

          Works like a charm! Thanks a lot  ;D

          1 Reply Last reply Reply Quote 0
          • First post
            Last post

          Products

          • Platform Overview
          • TNSR
          • pfSense
          • Appliances

          Services

          • Training
          • Professional Services

          Support

          • Subscription Plans
          • Contact Support
          • Product Lifecycle
          • Documentation

          News

          • Media Coverage
          • Press
          • Events

          Resources

          • Blog
          • FAQ
          • Find a Partner
          • Resource Library
          • Security Information

          Company

          • About Us
          • Careers
          • Partners
          • Contact Us
          • Legal
          Our Mission

          We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

          Subscribe to our Newsletter

          Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

          © 2021 Rubicon Communications, LLC | Privacy Policy