    I have a site2site openvpn connection. Local network is and remote network is Tunnel network is

    I can ping everything from the firewall because the request come from interface. The same on both sites.

    From 0 (local) can not ping 103 (remote) but can ping (local tunnel interface) and (remote tunnel interface). The same on the remote site. Is so strange… I can see routes in the routing table.... Every thing is open on openvpn firewall tab...

    Any idea?

    And what are you trying to ping on the other side?  Most window machines firewall by default block ping if not from local network..

  • This isn't the problem. When I do a ping from local pfsense ( to ( remote lan pfsense) or to 103.5 (linux machine) it works. But when from the local pfsense I do a ping with -S (lan of the local pfsense) don't work.

  • Normally, this is all very simple once you've got your setup talking to any  remote devices through the OpenVPN tunnel, it's all good.

    Perhaps we've got a little terminology confusion about your setup, never mind remote and local (which is prone to confusing which is which in a conversation).
    Let's try:

          pfs-LANA -
          Win1    - 192.168.0.??
          Linux1  - 192.168.0.??

    OpenVPN Tunnel

          pfs-LANB -
          Win2 - 192.168.103.??
          Linux2 -

    Your description suggests you've been doing your pings from one or the other of the pfSense boxes, either via the GUI-Diagnostics Ping or (better) via a shell login.
    Normally, there's no need to login/use/shell into the 10.2.0.x tunnel addresses if you've got connectivity working at all.
    There's usually no issue getting to either of the pfs-LANA/LANB interfaces from the other, so you can usually shell into both quite easily via their normal LAN Nics.

    As johnpoz suggested the issues are normally somewhere other than the OpenVPN tunnel once you get this far.

    Can you describe exactly what you've done to this point (using the above terminology to avoid confusion)?
    You say you can ping the Linux2 box, can you shell into it and try your pings from there?
    Do you actually have a Linux1 box you can try your pings from as well?

    You are right. Site A and Site B is as you describe. Here the results of the test:

    From pfsense A:

    ping -S ->No answer
    ping -S (Tunel ip in pfesne B) -> Answer
    ping -S -> answer

    From linux machine ( in A

    ping -> No answer
    ping -> Answer

    From pfsense B, same result


  • Finaly, erasing and re doing the configuration now it works right…

