URGENT: IPsec over Openvpn tunnel not working
Posted: Fri Jun 03, 2016 2:46 pm
Hi guys,
I'm quite new to Openvpn and i'm actually facing an issue i can't solve on my own, and before investigating hardware deeper, i would like to ensure i'm not facing a simple incompatibility between IPSec and Openvpn.
We are actually running Openvpn tunnels between distant router and a pfsense server. It works great and distant router are getting WAN access from pfsense server. So in this configuration, a client connected to a distant router (Openvpn client) is using the WAN accesss coming from the pfsense server (which is owning the Openvpn server).
Client -(LAN)-> Router -(Openvpn tunnel UDP/TUN)-> pfsense -> WAN access
We have clients that want to set IPSec tunnels with third systems over our (Router -> pfsense) Openvpn tunnel, and it is not working.
I've tried to search over forums and online doc but didn't found any example like mine.
In the same time i test other tunnels protocols passing through our configuration (Router -(Openvpn tunnel)-> pfsense -> WAN) and i can establish working tunnels with Openvpn (TCP/UDP), SSTP, PPTP... but it is not working at all with IPSec protocol.
Maybe that i'm missing something but i'm wondering if there is any limitation in using Openvpn for doing what i'm trying to, i mean having an Openvpn tunnel delivering WAN access and using it to establish an IPSec connection and passing IPSec traffic.
For your information, there is no firewalling rules either in the router or in pfsense server.
If i'm not clear enough let me know, any help would be greatly appreciated.
Many thanks for all, Sebastien
I'm quite new to Openvpn and i'm actually facing an issue i can't solve on my own, and before investigating hardware deeper, i would like to ensure i'm not facing a simple incompatibility between IPSec and Openvpn.
We are actually running Openvpn tunnels between distant router and a pfsense server. It works great and distant router are getting WAN access from pfsense server. So in this configuration, a client connected to a distant router (Openvpn client) is using the WAN accesss coming from the pfsense server (which is owning the Openvpn server).
Client -(LAN)-> Router -(Openvpn tunnel UDP/TUN)-> pfsense -> WAN access
We have clients that want to set IPSec tunnels with third systems over our (Router -> pfsense) Openvpn tunnel, and it is not working.
I've tried to search over forums and online doc but didn't found any example like mine.
In the same time i test other tunnels protocols passing through our configuration (Router -(Openvpn tunnel)-> pfsense -> WAN) and i can establish working tunnels with Openvpn (TCP/UDP), SSTP, PPTP... but it is not working at all with IPSec protocol.
Maybe that i'm missing something but i'm wondering if there is any limitation in using Openvpn for doing what i'm trying to, i mean having an Openvpn tunnel delivering WAN access and using it to establish an IPSec connection and passing IPSec traffic.
For your information, there is no firewalling rules either in the router or in pfsense server.
If i'm not clear enough let me know, any help would be greatly appreciated.
Many thanks for all, Sebastien