This is probably something simple, but not sure what the issue is. I can’t ping the secondary external IP of VyOS1 from the client. The UniFi router has an IPSEC + BGP session to VyOS1 (VTI)
I have three routers connected in the topology below:
Client -->> UniFi (also running a VyOS spin-off) <----BGP—> VyOS1 <—BGP—> VyOS2
- No firewalls on routers on VyOS1, VyOS2
- UniFi/client can ping external IP of VyOS2 just fine, and is an exact clone of VyOS except the external IPs
- Can ping external IPs of VyOS1 if move to a different internet connection than Client (a.k.a. my uncle’s wifi)
- Each router has two IPs (the 2nd IP is a floating IP)
NAT rules on VyOS1 and VyOS2 —> are set to the 2nd IP. I’ve had no issue with this.
Update: this happens with the VPN is connected and online, not offline.