I feel like I am missing something simple, but am not sure. I have a UniFi router, and two VyOS machines that I am connecting in the pattern below
UniFi (192.168.2.0/24) <--------VPN mode = tunnel ----------> VyOS-1 (10.4.96.0/20) <—DMVPN-----> VyOS-2 (10.1.112.0/20)
I advertised the 192.168.2.0/24 as a static route in BGP and see it on the VyOS-1 and VyOS-2 instances.
I can ping from UniFi → VyOS-1, VyOS-1 → UniFi, and VyOS-1 → VyOS-2, VyOS-2 to VyOS-1. I am not sure why can’t reach VyOS-2 —> UniFi. The UniFi uses a trap based policy by default, so I’ve added the subnet of VyOS-2.
Could it be a NAT rule issue or traffic coming across with the incorrect address?