Koozali.org: home of the SME Server

openVPN SiteToSite

Offline mudra

  • ****
  • 78
  • +0/-0
openVPN SiteToSite
« on: May 06, 2014, 01:06:14 PM »
Dear All,

I have two smeservers (one remote for affa backup purposes) connecting through an Openvpn Sitetosite tunnel. This has worked without any problems for many months.

We have recently installed a new telephone system which needed to go onto a separte subnet - so I have installed an IPFire firewall box and set the smeserver to gateway only. I have portforwarded 1194 from the IPFire firewall but the tunnel does not reconnect.

Do I have to forward any other ports ? In principle should this approach work OR should I try and VPN to the IPFirewall now.

Please let me know if the above is not clear.

Murda.

Offline Daniel B.

  • *
  • 1,700
  • +0/-0
    • Firewall Services, la sécurité des réseaux
Re: openVPN SiteToSite
« Reply #1 on: May 06, 2014, 01:31:01 PM »
Hi. You mean you have your SME as a server only (and not gateway only) ?

I see no reason for it not to work.

- Check the logs /var/log/openvpn-s2s/<daemon ID>.log at both end, to see if it's a timeout or something else
- Check the tunnel is using port 1194 (as you can enter an arbitrary port...)
- the port forward from IPFire should be for UDP, not TCP (unless you changed it manually, OpenVPN s2s uses UDP)
- Last: you can try to reverse client and server. The SME behind IPfire can become the client so no port forwarding will be necessary (as it'll initiate the connection). But this require that you re-configure the tunnel at both ends

Regards, Daniel
C'est la fin du monde !!! :lol:

Offline mudra

  • ****
  • 78
  • +0/-0
Re: openVPN SiteToSite
« Reply #2 on: May 06, 2014, 02:12:34 PM »
Dear Daniel,

Thankyou for your quick reply. I have port-forwarded the port via TCP and UDP now !! I can see nothing in the logs and I will try and swap the client / server round overnight and see if that is going to work better.

I will let you know how things work out.

Murda

Offline mudra

  • ****
  • 78
  • +0/-0
Re: [SOLVED] - openVPN SiteToSite
« Reply #3 on: May 07, 2014, 06:40:19 PM »
Dear Daniel,

I swapped the client / server around and everything works as it should. Thanks for the advice.

Mudra

 :-P