timberdoodle
Gawd
- Joined
- Sep 22, 2008
- Messages
- 878
Hey [H]
I have a weird issue I'm working through and could use some help. I've got a site to site VPN tunnel setup using two Ubuntu servers running OpenVPN and acting as gateways. I've set up the routing such that when I am in one LAN, lets call my client 10.0.0.5, I can ping any client in the other LAN, lets call them 10.10.0.4 and 10.10.0.6. I can also ssh into them without any issue.
Now, I switch sides. I try to ping from the second LAN to the first. So from 10.10.0.4 to 10.0.0.5. I get no echo reply. No ssh.
I run tcpdump on the various parties involved. The echo replies are traveling from the 10.0.0.5 node, through the VPN tunnel out the tunnel interface on my VPN gateway in the first LAN, show as destined for the originating node, but that's as far as they get. For some reason they are not going out the LAN interface of the VPN gateway and are just being dumped on the floor.
I have made several attempts to modify iptables and sysctl.conf for ip forwarding and am striking out. Anyone have any idea what I could try?
I have a weird issue I'm working through and could use some help. I've got a site to site VPN tunnel setup using two Ubuntu servers running OpenVPN and acting as gateways. I've set up the routing such that when I am in one LAN, lets call my client 10.0.0.5, I can ping any client in the other LAN, lets call them 10.10.0.4 and 10.10.0.6. I can also ssh into them without any issue.
Now, I switch sides. I try to ping from the second LAN to the first. So from 10.10.0.4 to 10.0.0.5. I get no echo reply. No ssh.
I run tcpdump on the various parties involved. The echo replies are traveling from the 10.0.0.5 node, through the VPN tunnel out the tunnel interface on my VPN gateway in the first LAN, show as destined for the originating node, but that's as far as they get. For some reason they are not going out the LAN interface of the VPN gateway and are just being dumped on the floor.
I have made several attempts to modify iptables and sysctl.conf for ip forwarding and am striking out. Anyone have any idea what I could try?