Welcome, Guest. Please login or register.
Did you miss your activation email?
+  pfSense Forum
|-+  pfSense English Support» OpenVPN» OpenVPN site to site PKI partially up?
Username:
Password:
 
 

Pages: [1]   Go Down
  Print  
Author Topic: OpenVPN site to site PKI partially up?  (Read 486 times)
0 Members and 1 Guest are viewing this topic.
DaninND
Newbie
*
Offline Offline

Posts: 15


View Profile
« on: May 15, 2012, 03:03:26 pm »

Any help is greatly appreciated.
Two sites -- trying to (re)set up OpenVPN site to site with PKI. Routers at both are full install pfsense 2.0.1.

The tunnel seems to be up. Site A has OpenVPN server. Site B is OpenVPN client. Both are set to allow all traffic on the OpenVPN interface.
I have NAT redirects setup so I can SSH and webGUI to site B pfsense through the WAN (it beats driving back and forth).
Everything looks up from webGUI Status -> OpenVPN display at both sites. The routes appear to be correct at both sites -- the remote subnet is routed through the VPN gateway. I can ping site A from site B through SSH, but not through the webGUI or any computer on site B subnet. I can traceroute to site A LAN from site B SSH pfsense console AND webGUI.  I can't ping site B at all, by any means, from site A.
I used to have this setup with pfsense 1.2.3 at all sites and it was rock solid. I must be missing a setting somewhere?
Again, any help appreciated.
Logged
Nachtfalke
Hero Member
*****
Offline Offline

Posts: 2422


View Profile
« Reply #1 on: May 15, 2012, 03:56:04 pm »

(...)
I must be missing a setting somewhere?
(...)
The iroute command for the site B subnet on site B vpn client.
Logged
DaninND
Newbie
*
Offline Offline

Posts: 15


View Profile
« Reply #2 on: May 15, 2012, 04:42:52 pm »

Thanks for the suggestion.

Just tried adding in the iroute command...
The status under Status->OpenVPN changed to down and I could no longer ping from site B.
I already have "route [site B subnet] [subnet mask]" command in server under the advanced options.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

 

Page created in 0.027 seconds with 20 queries.