Community discussions

MikroTik App
 
bibawa
newbie
Topic Author
Posts: 28
Joined: Mon Oct 29, 2012 11:25 pm

Issue with OVPN between Mikrotik and PFSense

Thu Aug 09, 2018 7:24 pm

Hi,

I got a strange issue with a site-to-site vpn between a PFSense box and a Mikrotik device. The vpn itself is created with OpenVPN (server side = PFsense, client = Mikrotik)..
The simplified setup:

Image

The problem is as follow:

From Mikrotik side

* I can succesfully ping devices on the 192.168.100.0/24 subnet FROM THE MIKROTIK ITSELF
* I cannot ping devices on the 192.168.100.0/24 subnet from a PC behind the Mikrotik

On the MT static routes have been created to route traffic for 192.168.100.0/24 subnet over the ovpn tunnel interface, but the strange thing is.. When i start a tracert on a pc behind the MT it is as follows:
C:\Users\MIGRATIE>tracert 192.168.100.205

Tracing route to 192.168.100.205 over a maximum of 30 hops

  1    <1 ms    <1 ms    <1 ms  192.168.1.1
  2     *        *        *     Request timed out.
  3     *        *        *     Request timed out.
  4     *        *        *     Request timed out.
  5     *        *        *     Request timed out.
So traffic is forwarded to 1.1 (MT) and after that it seems he don't know what to do with the traffic..

I'm searching for a solution for a couple of hours now, I hope someone can help me out this ..

thanks!
 
User avatar
bramwittendorp
Member Candidate
Member Candidate
Posts: 101
Joined: Thu Jun 16, 2016 3:48 pm
Location: The Netherlands
Contact:

Re: Issue with OVPN between Mikrotik and PFSense

Thu Aug 09, 2018 7:43 pm

Please post the output of the following command, hiding stuff you don't want to share, like public IP-adresses or something like that.
/export hide-sensitive
That way we'll get a better understanding of your config and any problems that might occur.

Something that comes to mind immediatly: make sure you're having the correct firewall rules in the forward chain so traffic from and to the PFSense box can pass through the MikroTik.