Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

IPSEC VPN Routing traffic between multiples sites

Hi,

We need to establish a multiple site to site IPSEC VPN with a XG86w as the HQ.

Both remote sites have a TELTONIKA RUT240 router.

I am able to ping from HQ both remote sites, and from each remote site the HQ, but can’t ping a remote site from another remote site.

 

In the XG86w I have in the local subnet of each tunnel the local HQ network and the local network of the other remote site.

 

On the TELTONIKA RUT240 side, running ipsec status we can see that both are installed.

I'm clearly missing something.

Any help would be appreciated.

 

Alexandre



Added TAGs
[edited by: Raphael Alganes at 3:26 PM (GMT -7) on 7 Oct 2024]
Parents Reply
  • After this call, I made a few more tests, and found the following.

    HO with a netmask of /24 and both BO1 and BO2 with a netmask of /29 doesn't work. Not sure why, but changed BO1 to a /24 netmask, and it worked.

    Also discovered that the TELTONIKA device was masquerading WAN output packets. Tried the netmask /29 with masquerading on and off and it didn't solve the problem.

    So, now now I'm using a mask of /24 on all networks and it's working as it should. I believe that's a TELTONIKA implementation problem.

    Thanks to Sreenivasulu Naidu for his help (and patience).

Children
No Data