Hi Team
I’ve built a VPN from site A (VYOS) to site B (non VYOS). The tunnel is up, but traffic does not return.
Site A is 198.18.1.1 and Site B is 198.18.1.2.
Lets assume I cannot find out what the local LAN subnet is on 198.18.1.2.
I can see the traffic using a packet trace coming over the tunnel, but it just never sends anything back it also doesnt send the ping out, it just doesnt do anything. Just states no response seen. I think I need to do something with NAT to possibly get it back into the tunnel.
Can someone help me please?
KR
Jazzy
set vpn ipsec esp-group policy1 compression 'disable'
set vpn ipsec esp-group policy1 lifetime '1800'
set vpn ipsec esp-group policy1 mode 'tunnel'
set vpn ipsec esp-group policy1 pfs 'enable'
set vpn ipsec esp-group policy1 proposal 1 encryption 'aes256'
set vpn ipsec esp-group policy1 proposal 1 hash 'sha256'
set vpn ipsec esp-group policy2 compression 'disable'
set vpn ipsec esp-group policy2 lifetime '1800'
set vpn ipsec esp-group policy2 mode 'transport'
set vpn ipsec esp-group policy2 pfs 'enable'
set vpn ipsec esp-group policy2 proposal 1 encryption 'aes256'
set vpn ipsec esp-group policy2 proposal 1 hash 'sha256'
set vpn ipsec ike-group policy1 ikev2-reauth 'no'
set vpn ipsec ike-group policy1 key-exchange 'ikev2'
set vpn ipsec ike-group policy1 lifetime '3600'
set vpn ipsec ike-group policy1 mode 'aggressive'
set vpn ipsec ike-group policy1 proposal 1 dh-group '14'
set vpn ipsec ike-group policy1 proposal 1 encryption 'aes256'
set vpn ipsec ike-group policy1 proposal 1 hash 'sha256'
set vpn ipsec ipsec-interfaces interface 'eth1.1'
set vpn ipsec logging log-level '2'
set vpn ipsec site-to-site peer 198.18.1.2 authentication id '198.18.1.1'
set vpn ipsec site-to-site peer 198.18.1.2 authentication mode 'pre-shared-secret'
set vpn ipsec site-to-site peer 198.18.1.2 authentication pre-shared-secret 'xxxx'
set vpn ipsec site-to-site peer 198.18.1.2 authentication remote-id '[email protected]'
set vpn ipsec site-to-site peer 198.18.1.2 ike-group 'policy1'
set vpn ipsec site-to-site peer 198.18.1.2 local-address '198.18.1.1'
set vpn ipsec site-to-site peer 198.18.1.2 tunnel 0 allow-nat-networks 'disable'
set vpn ipsec site-to-site peer 198.18.1.2 tunnel 0 allow-public-networks 'disable'
set vpn ipsec site-to-site peer 198.18.1.2 tunnel 0 esp-group 'policy2'