Multi site vpn stopped working



  • I had it working and all of the sudden stopped. May have something to do with changing outbound nat to hybrid because wii wouldn't connect to internet.  Both client sites connect to server site. vpn status shows vpn up on both. Seems to be a routing issue. Tracert on client 1 internal and external ips are totally different. The internal looks like it goes to NY. I'm in CA. The external is good.

    Client 2 internal looks to be a loop with the virtual vpn interface.

    I did get it to work by rebooting hyperv host. I could ping from server site to client 2. When I went to client 2 and ping to server, it killed the link and nothing worked. Pinging from server to client 2 afterword showed ttl expired in transit and went into the loop.

    Server site
    192.168.1.x

    client 1
    10.10.1.x
    virtual 192.168.21.0/30

    Tracert to client 1
    Tracing route to 10.10.1.1 over a maximum of 30 hops

    1    <1 ms    <1 ms    <1 ms  192.168.1.1
      2    4 ms    1 ms    1 ms  L100.LSANCA-VFTTP-85.verizon-gni.net [72.67.127.1]
      3    6 ms    6 ms    6 ms  g1-6-4-5.lsanca-lcr-21.verizon-gni.net [100.41.128.36]
      4    *        *        *    Request timed out.
      5    70 ms    80 ms    69 ms  0.ae5.ny5030-bb-rtr1.alter.net [152.63.0.54]
      6    74 ms    74 ms    74 ms  so-6-0-0-0.pskn-core-rtr1.verizon-gni.net [130.81.20.235]
      7    73 ms    73 ms    72 ms  10.10.1.1

    Tracert to client 1 wan ip
    Tracing route to xxx.xxx.xxx [xxx.xxx.xxx.xxx]
    over a maximum of 30 hops:

    1    <1 ms    <1 ms    <1 ms  192.168.1.1
      2    2 ms    1 ms    1 ms  L100.LSANCA-VFTTP-85.verizon-gni.net [72.67.127.1]
      3    2 ms    1 ms    1 ms  pool-173-67-xxx-xx.lsanca.fios.verizon.net [xxx.xxx.xxx.xxx]

    Trace complete.

    client 2
    10.10.2.x
    virtual 192.168.22.0/30

    Tracert to client 2
    1    <1 ms    <1 ms    <1 ms  192.168.1.1
      2    2 ms    1 ms    1 ms  192.168.21.2
      3    1 ms    1 ms    1 ms  192.168.21.1
      4    3 ms    2 ms    3 ms  192.168.21.2
      5    3 ms    2 ms    2 ms  192.168.21.1
      6    4 ms    4 ms    5 ms  192.168.21.2

    Tracing route to xxx.xxx.xxx [xxx.xxx.xxx.xxx]
    over a maximum of 30 hops:

    1    <1 ms    <1 ms    <1 ms  192.168.1.1
      2    2 ms    1 ms    1 ms  L100.LSANCA-VFTTP-85.verizon-gni.net [72.67.127.1]
      3    6 ms    6 ms    6 ms  G1-6-4-5.LSANCA-LCR-22.verizon-gni.net [100.41.128.38]
      4    *        *        *    Request timed out.
      5    13 ms    15 ms    12 ms  xxx.xxx.xxx [xxx.xxx.xxx.xxx]



  • I did make 2 open vpn servers on different ports and have each client connect to the separate one. I don't know if that is how it's supposed to be. The pfsense forums were down when I configured this the other day.

    Client 2 vpn config

    IPv4 Tunnel Network 192.168.22.0/24

    IPv4 Remote Network 192.168.1.0/24,10.10.1.0/24

    Client 1 vpn config

    IPv4 Tunnel Network 192.168.21.0/24

    IPv4 Remote Network 192.168.1.0/24,10.10.2.0/24

    Server vpn config
    client 1:
    IPv4 Tunnel Network 192.168.21.0/24

    IPv4 Local Network/s 192.168.1.0/24

    IPv4 Remote Network/s 10.10.1.0/24,10.10.2.0/24

    client 2:
    IPv4 Tunnel Network 192.168.21.0/24

    IPv4 Local Network/s 192.168.1.0/24

    IPv4 Remote Network/s 10.10.2.0/24,10.10.1.0/24