Monday, November 15, 2021

Unable to connect from side A to B, but not from B to A through IPsec tunnel

Hello,

Long time lurker of this subreddit here. I am trying to solve an issue that I have for some time now. Asked some colleagues to check this issue out for me but unfortunately they can't pinpoint the issue. Hopefully someone from this subreddit can help me!

I want to create a new network for a customer. This customers' network consists of:

  • A management VLAN (VLAN 1, default: 10.10.1.0/24)
  • A Company network (VLAN 1000: 172.18.1.0/24)
  • A Guest network (VLAN 2000: 192.168.1.0/24)
  • A Systems network (VLAN 3000: 10.0.1.0/24).The company network is the primary network, this network will be able to communicate with our datacenter through an IPsec tunnel.

All the networks noted above do have access to the internet. From the datacenter (A) I am able to reach the company network (B). Unfortunately I am not able to initiate a connection from the company network (B) to the datacenter network (A).

The customer is using a Unifi Security Gateway (USG), we are using a virtual PfSense firewall in our datacenter. I tried the following to solve this issue:

  • Checked the IPsec tunnel to check if the configuration is correct. The tunnel is online.
  • Static routes are applied. I also tried to create them manually on the Windows machines just in case.
  • The firewall rules are tested by creating any/any rules on traffic between the 2 networks.

Is there something else I can do to solve or troubleshoot this issue? I am out of options :)

You can find a small drawing of my network below:

https://imgur.com/a/kQkqLjD



No comments:

Post a Comment