Netgate m1n1wall

Author Topic: OpenVPN site to site - no joy- VPN up but no talk  (Read 3897 times)

0 Members and 1 Guest are viewing this topic.

Offline cjbujold

  • Jr. Member
  • **
  • Posts: 58
  • Karma: +0/-0
    • View Profile
OpenVPN site to site - no joy- VPN up but no talk
« on: February 21, 2012, 10:00:52 am »
Created a site to site OpenVPN using PFSense as the router at both locations(v2.0.1) both sites connect without a problem (sharedkey).  I can ping the 10.0.8.1 or 10.0.8.2 from both sides without a problem.  No errors reported in log for openvpn or firewall log.

The issue is that neither side can ping or access PC's on the other network.  I can ping the 10.0.8.X router from the remote locations but cannot ping the actual Internal IP of the router (192.168.0.1 and 192.168.120.1).  I thought it was a routing issue so checked the route table on both PFsense device and both have an entry for the 10.0.8.1 and 10.0.8.2 route to the router and a third being the subnet route of the remote office to the remote 10.0.8.X router.   Verified each PFsense server and both have a Openvpn route that states anything to anything.

I'm at a lost to find why we cannot actually connect to any of the remote PC's, yet the openvpn tunnel is up.  The setup used is from the user guide available on the PFsense web site. (http://doc.pfsense.org/index.php/OpenVPN_Site-to-Site_%28Shared_Key,_2.0%29)

Any help would be appreciated

Thanks
cjb

Offline Nachtfalke

  • Hero Member
  • *****
  • Posts: 2753
  • Karma: +0/-0
    • View Profile
Re: OpenVPN site to site - no joy- VPN up but no talk
« Reply #1 on: February 21, 2012, 12:30:10 pm »
On the OpenVPN Server with IP you need to add a route to the network behind the OpenVPN client (10.0.8.2)
On OpenVPN Server go to custom Options and add:
Code: [Select]
route 192.168.120.0 255.255.255.0;Probably you do not need this entry because you entered this network in "Remote Network" in the OpenVPN Server options.

On the client OpenVPN add this:

Code: [Select]
route 192.168.0.0 255.255.255.0;
iroute 192.168.120.0 255.255.255.0;


Check and allow traffic on bothe firewalls for OpenVPN.
For testing purposes a simple "Allow any to any" rule should work.

Offline kartweel

  • Jr. Member
  • **
  • Posts: 30
  • Karma: +0/-0
    • View Profile
Re: OpenVPN site to site - no joy- VPN up but no talk
« Reply #2 on: June 15, 2012, 11:31:22 pm »
Hi,

I have this exact issue. The proposed solution doesn't work for me. If I add iroute on the client it says it is not valid.

Did you end up getting this working?

Offline kartweel

  • Jr. Member
  • **
  • Posts: 30
  • Karma: +0/-0
    • View Profile
Re: OpenVPN site to site - no joy- VPN up but no talk
« Reply #3 on: June 16, 2012, 01:01:22 am »
So I ended up assigning an interface, which then allowed any PC to access the server on the other end, but not the remote network. So I then created a gateway and added a static route at each end to point to the other network, and gave my interface a static IP then it worked. So it really seems that I needed to duplicate the OpenVPN configuration manually for it to work. At least it works I guess... :)

Offline jockwatson

  • Newbie
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
Re: OpenVPN site to site - no joy- VPN up but no talk
« Reply #4 on: August 03, 2012, 05:35:02 am »
Is that really the only way to get this to work for even a simple site to site?

Can I clarify with you kartweel?

Did you assign interfaces on both client and server, and did you then assign the same static IP to the interface(s) as the OpenVPN would have been set to (so 10.0.8.1 at the server end on my config)?

Then you add routes at each end?

Offline heper

  • Hero Member
  • *****
  • Posts: 675
  • Karma: +0/-0
    • View Profile
Re: OpenVPN site to site - no joy- VPN up but no talk
« Reply #5 on: August 03, 2012, 08:27:45 am »
entering the remote an local networks on both ends should do the trick for simple site-2-site vpn's using openvpn.

i've done this a dozen times without fail