Netgate SG-1000 microFirewall

Author Topic: Half working routing  (Read 153 times)

0 Members and 1 Guest are viewing this topic.

Offline BEB Consulting

  • Jr. Member
  • **
  • Posts: 39
  • Karma: +0/-0
    • View Profile
Half working routing
« on: October 30, 2017, 05:57:08 pm »
I have a AWS site and a Local Office Site. I have OpenVPN setup with working connections, I also have BGP configured for routing.

Everything is connected. However routing is acting a bit weird.

I am able to ping From the local office site to AWS just fine.....however I am NOT able to ping from the AWS site to the local office.

Not sure what I am missing.

I tried adding a static route on the AWS side and added the right networks to the security groups. Still not able to route.

Pinging anything in the 173.31.0.0/16 from the 10.0.96.0/19 network works just fine, but pinging anything in the 10.0.96.0/19 from anywhere in the 173.31.0.0/16 network fails.

Pinging from the AWS PfSense works to anything in the 10.0.96.0/19 network, and pinging from the local Pfsense to 173.31.0.0/16 works as well if done from the PFsense.

Not sure what I am missing....

Diagrams attached.

Any suggestions.....Don't have full AWS support plan yet....thought I would check here first.

Offline chpalmer

  • Hero Member
  • *****
  • Posts: 1748
  • Karma: +93/-3
    • View Profile
    • Home of Cablenut
Re: Half working routing
« Reply #1 on: October 30, 2017, 06:53:49 pm »
Once the tunnel is up it should be all about what you allow..  what do yor vpn firewall rules look like?
P.S. statements made by me are not necessarily condoned by the management of this fine organization.  http://badmodems.com

Offline BEB Consulting

  • Jr. Member
  • **
  • Posts: 39
  • Karma: +0/-0
    • View Profile
Re: Half working routing
« Reply #2 on: October 30, 2017, 07:39:43 pm »
Here are my rules for the AWS (AWS) and Local Site (Site)

Offline BEB Consulting

  • Jr. Member
  • **
  • Posts: 39
  • Karma: +0/-0
    • View Profile
Re: Half working routing
« Reply #3 on: November 06, 2017, 10:25:43 am »
Just making a bump....

Just wondering if anyone has suggestions.