<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Traffic from Road Warrior to Branch to HQ]]></title><description><![CDATA[<p dir="auto">Something tells me this should be easy but I often over-complicate things.</p>
<p dir="auto">I connect to a branch office via OpenVPN to my work LAN.  The work LAN connects to a server via a site-to-site OpenVPN connection (HQ)  At HQ is a DNS server (Server 2012 R2).  From my remote connection I am unable to get DNS queries answered from the server at HQ.  I am unable to get a reply from nslookup or ping when I try to find a device at HQ.</p>
<p dir="auto">*******                ********                *****</p>
<ul>
<li>HOME * &gt;–-----&gt;* Branch <em>&gt;-------&gt;</em> HQ *<br />
*******                ********                  *****</li>
</ul>
<p dir="auto">Do I need to do anything special that allows road warrior traffic to pass, ultimately, to the HQ location?  I have Unbound setup at the pfSense 2.2.4 box at Branch.  Within the config of Unbound I have defined the LANs that are able to access the service.  Within the pfSense box at Branch  I have defined the server at HQ as a DNS server and told Unbound to "enable forwarding mode".  Do I need to manually push the route to the road warrior connections?</p>
<p dir="auto">I do specify DNS servers within the OpenVPN config for the remote users; I specify the branch (10.10.100.1) and the HQ (10.10.10.29).</p>
<p dir="auto">If I'm at Branch all is good.  I can nslookup &lt;host name=""&gt;and it relates the server at HQ and the correct IP address.&lt;/host&gt;</p>
]]></description><link>https://forum.netgate.com/topic/90104/traffic-from-road-warrior-to-branch-to-hq</link><generator>RSS for Node</generator><lastBuildDate>Sun, 19 Apr 2026 09:00:09 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/90104.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 08 Oct 2015 23:41:52 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Traffic from Road Warrior to Branch to HQ on Thu, 08 Oct 2015 23:57:08 GMT]]></title><description><![CDATA[<p dir="auto">thank you for the directions!  Much appreciated.</p>
]]></description><link>https://forum.netgate.com/post/575716</link><guid isPermaLink="true">https://forum.netgate.com/post/575716</guid><dc:creator><![CDATA[awsiemieniec]]></dc:creator><pubDate>Thu, 08 Oct 2015 23:57:08 GMT</pubDate></item><item><title><![CDATA[Reply to Traffic from Road Warrior to Branch to HQ on Thu, 08 Oct 2015 23:52:29 GMT]]></title><description><![CDATA[<p dir="auto">HQ needs an openvpn route to HOME with an iroute for the same to Branch<br />
HOME needs an openvpn route to HQ with an iroute for the same to Branch</p>
<p dir="auto">For connections from HOME to HQ, there need to be OpenVPN firewall rules permitting the traffic on Branch from HOME and on HQ from Branch.</p>
<p dir="auto">Regarding your second post, unbound is intended to be a caching resolver, not an authoritative zone master/slave.  What you probably want to do is forward the domain's domain (and probably the in-addr zones) to your 2012R2 DNS server.</p>
]]></description><link>https://forum.netgate.com/post/575715</link><guid isPermaLink="true">https://forum.netgate.com/post/575715</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Thu, 08 Oct 2015 23:52:29 GMT</pubDate></item><item><title><![CDATA[Reply to Traffic from Road Warrior to Branch to HQ on Thu, 08 Oct 2015 23:46:46 GMT]]></title><description><![CDATA[<p dir="auto">I would really like the two DNS servers (unbound, Server 2012 R2) to update each other so they both have a current copy of the zone but I have yet to see that happen.  Can it?  With that working I believe this would be a moot point.  (?)</p>
]]></description><link>https://forum.netgate.com/post/575713</link><guid isPermaLink="true">https://forum.netgate.com/post/575713</guid><dc:creator><![CDATA[awsiemieniec]]></dc:creator><pubDate>Thu, 08 Oct 2015 23:46:46 GMT</pubDate></item></channel></rss>