OpenVPN site-to-site between 2 VyOS (same LAN subnet | No overlapping IPs)

My configuration for openvpn is not working as expected and I am suspecting that I might have not configured something right.

I want to PC-A to be able to ping PC-B

VYOS-A configuration:
vyos@vyos-A# show inter
ethernet eth0 {
address 10.1.1.10/24
hw-id 00:0c:29:e4:5b:e0
}
ethernet eth1 {
address 192.168.1.251/24
hw-id 00:0c:29:e4:5b:ea
}
ethernet eth2 {
hw-id 00:0c:29:e4:5b:f4
}
loopback lo {
}
openvpn vtun10 {
local-address 192.168.10.1 {
}
local-host 10.1.1.10
local-port 8000
mode site-to-site
persistent-tunnel
protocol udp
remote-address 192.168.10.2
remote-host 10.1.1.20
shared-secret-key-file /config/auth/mysite.key
}
[edit]

VYOS-A configuration:
vyos@vyos-B# show inter
ethernet eth0 {
address 10.1.1.20/24
hw-id 00:0c:29:31:d3:32
}
ethernet eth1 {
address 192.168.1.252/24
hw-id 00:0c:29:31:d3:3c
}
ethernet eth2 {
hw-id 00:0c:29:31:d3:46
}
loopback lo {
}
openvpn vtun10 {
local-address 192.168.10.2 {
}
local-port 8000
mode site-to-site
persistent-tunnel
protocol udp
remote-address 192.168.10.1
remote-host 10.1.1.10
shared-secret-key-file /config/auth/mysite.key
}
[edit]

Not using NAT, Not using Firewall.

Any Suggestions? :slightly_smiling_face:

Hi,

the both eth1 networks on Side A and B are two different Layer2 domains so you need NAT.
Or, but i don’t tested or used it, you bridge eth1 to the vtun10 interface.
https://docs.vyos.io/en/latest/interfaces/bridge.html

I am actually was trying to avoid double NAT as it is a headache in troubleshooting network issues.

That is a good idea, I will try it.

I forgot to mention, openVPN link is not up, I can’t ping 192.168.10.2 from VyOS-A

vyos@vyos-A:~$ show openvpn site-to-site status

OpenVPN client status on vtun10 []

Remote CN       Remote IP       Tunnel IP       TX byte RX byte Connected Since
---------       ---------       ---------       ------- ------- ---------------
None (PSK)      10.1.1.20       192.168.10.2        420       0 N/A

vyos@vyos-B:~$ show openvpn site-to-site status

OpenVPN client status on vtun10 []

Remote CN       Remote IP       Tunnel IP       TX byte RX byte Connected Since
---------       ---------       ---------       ------- ------- ---------------
None (PSK)      10.1.1.10       192.168.10.1        540       0 N/A