Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
pfSense Forum
pfSense English Support
»
OpenVPN
»
OpenVPN site to site PKI partially up?
Username:
Password:
1 Hour
1 Day
1 Week
1 Month
Forever
Home
Help
Search
Login
Register
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: OpenVPN site to site PKI partially up? (Read 486 times)
0 Members and 1 Guest are viewing this topic.
DaninND
Newbie
Offline
Posts: 15
OpenVPN site to site PKI partially up?
«
on:
May 15, 2012, 03:03:26 pm »
Any help is greatly appreciated.
Two sites -- trying to (re)set up OpenVPN site to site with PKI. Routers at both are full install pfsense 2.0.1.
The tunnel seems to be up. Site A has OpenVPN server. Site B is OpenVPN client. Both are set to allow all traffic on the OpenVPN interface.
I have NAT redirects setup so I can SSH and webGUI to site B pfsense through the WAN (it beats driving back and forth).
Everything looks up from webGUI Status -> OpenVPN display at both sites. The routes appear to be correct at both sites -- the remote subnet is routed through the VPN gateway. I can ping site A from site B through SSH, but not through the webGUI or any computer on site B subnet. I can traceroute to site A LAN from site B SSH pfsense console AND webGUI. I can't ping site B at all, by any means, from site A.
I used to have this setup with pfsense 1.2.3 at all sites and it was rock solid. I must be missing a setting somewhere?
Again, any help appreciated.
Logged
Nachtfalke
Hero Member
Offline
Posts: 2422
Re: OpenVPN site to site PKI partially up?
«
Reply #1 on:
May 15, 2012, 03:56:04 pm »
Quote from: DaninND on May 15, 2012, 03:03:26 pm
(...)
I must be missing a setting somewhere?
(...)
The iroute command for the site B subnet on site B vpn client.
Logged
DaninND
Newbie
Offline
Posts: 15
Re: OpenVPN site to site PKI partially up?
«
Reply #2 on:
May 15, 2012, 04:42:52 pm »
Thanks for the suggestion.
Just tried adding in the iroute command...
The status under Status->OpenVPN changed to down and I could no longer ping from site B.
I already have "route [site B subnet] [subnet mask]" command in server under the advanced options.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Administrative
-----------------------------
=> Forum rules
=> Messages from the pfSense Team
=> Feedback
-----------------------------
pfSense English Support
-----------------------------
=> Installation and Upgrades
=> General Questions
=> 2.1 Snapshot Feedback and Problems
=> Post a bounty
===> Completed Bounties
===> Expired/Withdrawn Bounties
=> Hardware
=> Firewalling
=> NAT
=> CARP/VIPs
=> Routing and Multi WAN
=> Traffic Shaping
=> DHCP and DNS
=> IPv6
=> IPsec
=> PPTP
=> PPPoE Server
=> Captive Portal
=> webGUI
=> Wireless
=> SNMP
=> Packages
=> Virtualization installations and techniques
=> OpenVPN
=> Gaming
-----------------------------
Development/Documentation
-----------------------------
=> Documentation
=> Development
-----------------------------
General Category
-----------------------------
=> General Discussion
-----------------------------
International Support
-----------------------------
=> Indonesian
=> Deutsch
=> Español
=> Français
=> Italiano
=> Russian
=> Nederlands
=> Norwegian
=> Portuguese
=> Polish
=> Romanian
=> Swedish
=> Turkish
-----------------------------
Retired
-----------------------------
=> 1.2.3-PRERELEASE-TESTING snapshots - RETIRED
=> 1.2.1-RC Snapshot Feedback and Problems-RETIRED
=> 2.0-RC Snapshot Feedback and Problems - RETIRED
=> DNS Server testing area - RETIRED
Loading...