Page 1 of 1

Site to Site problems.

Posted: Thu Dec 22, 2011 4:35 am
by tehbublitz
Ok Computers from both networks can ping each other.

The client and server can ping each other but not other devices...They respond to pings if they are the destination NOT the source.

So whats happening is when you ping from the client or server the source packet is the tunnel interface, not the LAN interface. So other devices on each network does not know about the tunnel interface network just their own and the other end of the VPN.

I could just add a route on both ends, but the server will have 2 tunnels and host cluster witness file shares. This is a hosted machine so I don't want to buy 1 machine for just OpenVpn and another to host file shares.

So I need the server to source packets with its LAN address not its tunnel address even if its going to the remote network.

Is such a thing possible?

Re: Site to Site problems.

Posted: Sun Dec 25, 2011 11:16 am
by Mimiko
Is such a thing possible?
Yes, using iptables and masquerading.

Re: Site to Site problems.

Posted: Thu Jan 05, 2012 10:27 pm
by flatlining.theory
Hi. I did not know that this is possible. Thank you for sharing the information. =)

Re: Site to Site problems.

Posted: Sat Jan 07, 2012 5:29 am
by healthydiets
Thanks a lot. It was helpful for me too.

Re: Site to Site problems.

Posted: Sat Jan 07, 2012 8:59 am
by Mimiko
lupitarupert wrote:but how??
See method 4 from topic9465.html

Re: Site to Site problems.

Posted: Sun Jan 08, 2012 4:20 am
by fanbi
Mimiko wrote:
Is such a thing possible?
Yes, using iptables and masquerading.
Yes but generally the masquerading isn't very efficient. Unless you know of a better way to do it than I do...

Re: Site to Site problems.

Posted: Sun Jan 08, 2012 8:08 am
by Mimiko
fanbi wrote:Unless you know of a better way to do it than I do...
Using netmask option of iptables.

Re: Site to Site problems.

Posted: Sat May 12, 2012 7:13 am
by Dwayne
Recheck all the software...may be hardware connecting software....... or there can be virus problem into the system....