Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Multi site vpn stopped working

    OpenVPN
    1
    2
    504
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      delta9 last edited by

      I had it working and all of the sudden stopped. May have something to do with changing outbound nat to hybrid because wii wouldn't connect to internet.  Both client sites connect to server site. vpn status shows vpn up on both. Seems to be a routing issue. Tracert on client 1 internal and external ips are totally different. The internal looks like it goes to NY. I'm in CA. The external is good.

      Client 2 internal looks to be a loop with the virtual vpn interface.

      I did get it to work by rebooting hyperv host. I could ping from server site to client 2. When I went to client 2 and ping to server, it killed the link and nothing worked. Pinging from server to client 2 afterword showed ttl expired in transit and went into the loop.

      Server site
      192.168.1.x

      client 1
      10.10.1.x
      virtual 192.168.21.0/30

      Tracert to client 1
      Tracing route to 10.10.1.1 over a maximum of 30 hops

      1    <1 ms    <1 ms    <1 ms  192.168.1.1
        2    4 ms    1 ms    1 ms  L100.LSANCA-VFTTP-85.verizon-gni.net [72.67.127.1]
        3    6 ms    6 ms    6 ms  g1-6-4-5.lsanca-lcr-21.verizon-gni.net [100.41.128.36]
        4    *        *        *    Request timed out.
        5    70 ms    80 ms    69 ms  0.ae5.ny5030-bb-rtr1.alter.net [152.63.0.54]
        6    74 ms    74 ms    74 ms  so-6-0-0-0.pskn-core-rtr1.verizon-gni.net [130.81.20.235]
        7    73 ms    73 ms    72 ms  10.10.1.1

      Tracert to client 1 wan ip
      Tracing route to xxx.xxx.xxx [xxx.xxx.xxx.xxx]
      over a maximum of 30 hops:

      1    <1 ms    <1 ms    <1 ms  192.168.1.1
        2    2 ms    1 ms    1 ms  L100.LSANCA-VFTTP-85.verizon-gni.net [72.67.127.1]
        3    2 ms    1 ms    1 ms  pool-173-67-xxx-xx.lsanca.fios.verizon.net [xxx.xxx.xxx.xxx]

      Trace complete.

      client 2
      10.10.2.x
      virtual 192.168.22.0/30

      Tracert to client 2
      1    <1 ms    <1 ms    <1 ms  192.168.1.1
        2    2 ms    1 ms    1 ms  192.168.21.2
        3    1 ms    1 ms    1 ms  192.168.21.1
        4    3 ms    2 ms    3 ms  192.168.21.2
        5    3 ms    2 ms    2 ms  192.168.21.1
        6    4 ms    4 ms    5 ms  192.168.21.2

      Tracing route to xxx.xxx.xxx [xxx.xxx.xxx.xxx]
      over a maximum of 30 hops:

      1    <1 ms    <1 ms    <1 ms  192.168.1.1
        2    2 ms    1 ms    1 ms  L100.LSANCA-VFTTP-85.verizon-gni.net [72.67.127.1]
        3    6 ms    6 ms    6 ms  G1-6-4-5.LSANCA-LCR-22.verizon-gni.net [100.41.128.38]
        4    *        *        *    Request timed out.
        5    13 ms    15 ms    12 ms  xxx.xxx.xxx [xxx.xxx.xxx.xxx]

      1 Reply Last reply Reply Quote 0
      • D
        delta9 last edited by

        I did make 2 open vpn servers on different ports and have each client connect to the separate one. I don't know if that is how it's supposed to be. The pfsense forums were down when I configured this the other day.

        Client 2 vpn config

        IPv4 Tunnel Network 192.168.22.0/24

        IPv4 Remote Network 192.168.1.0/24,10.10.1.0/24

        Client 1 vpn config

        IPv4 Tunnel Network 192.168.21.0/24

        IPv4 Remote Network 192.168.1.0/24,10.10.2.0/24

        Server vpn config
        client 1:
        IPv4 Tunnel Network 192.168.21.0/24

        IPv4 Local Network/s 192.168.1.0/24

        IPv4 Remote Network/s 10.10.1.0/24,10.10.2.0/24

        client 2:
        IPv4 Tunnel Network 192.168.21.0/24

        IPv4 Local Network/s 192.168.1.0/24

        IPv4 Remote Network/s 10.10.2.0/24,10.10.1.0/24

        1 Reply Last reply Reply Quote 0
        • First post
          Last post

        Products

        • Platform Overview
        • TNSR
        • pfSense
        • Appliances

        Services

        • Training
        • Professional Services

        Support

        • Subscription Plans
        • Contact Support
        • Product Lifecycle
        • Documentation

        News

        • Media Coverage
        • Press
        • Events

        Resources

        • Blog
        • FAQ
        • Find a Partner
        • Resource Library
        • Security Information

        Company

        • About Us
        • Careers
        • Partners
        • Contact Us
        • Legal
        Our Mission

        We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

        Subscribe to our Newsletter

        Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

        © 2021 Rubicon Communications, LLC | Privacy Policy