LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 04-05-2013, 03:45 PM   #1
Mark L. Wise
LQ Newbie
 
Registered: Jan 2010
Distribution: Fedora
Posts: 10

Rep: Reputation: 0
New install - OpenVPN unable to ping remote side


Hello!

I have installed OpenVPN (my first installation) on a pair of Fedora Core 17 boxes. I used the GUI Network Manager to set up the VPN on both ends.

While everything seems to be set up correctly, I am unable to ping the remote side of the net from either machine.

I have confirmed that the tcp packets are going out the VPN (tun0) through the public internet and arriving at the remote machine (tcpdump on the remote public IP). However, the packets are not coming out of the remote public IP (em0) and getting to the remote tun0.

I have ipforwarding on
I am using system-config-firewall (which uses iptables) and I believe that I have the appropriate rules to allow packets to move from em0 to tun0, etc.

I am looking for ideas of where to go from here in my debugging.

Thanks in advance for any help you can give.

Mark
 
Old 04-07-2013, 11:21 AM   #2
Lexus45
Member
 
Registered: Jan 2010
Distribution: Debian, Centos, Ubuntu, Slackware
Posts: 361
Blog Entries: 3

Rep: Reputation: 48
Quote:
Originally Posted by Mark L. Wise View Post
I used the GUI Network Manager to set up the VPN on both ends.
Hello.
If you just need to connect only two machines, the easiest way is this: http://openvpn.net/index.php/open-so...ini-howto.html


Quote:
Originally Posted by Mark L. Wise View Post
Hello!
I have ipforwarding on
I am using system-config-firewall (which uses iptables) and I believe that I have the appropriate rules to allow packets to move from em0 to tun0, etc.
I'm not sure you need to have ip forwarding turned on, until you decide to route, for example, traffic from your LAN through OpenVPN link.

You just need to allow UDP/1194 incoming traffic on the box which is the server. (I hope that any outgoing traffic is allowed on the client, or at least traffic to UDP port 1194 :)
And allow any incoming (and outgoing) traffic on tun0 interfaces on both boxes, to be able to do anything inside your VPN link.
 
Old 04-07-2013, 08:07 PM   #3
Mark L. Wise
LQ Newbie
 
Registered: Jan 2010
Distribution: Fedora
Posts: 10

Original Poster
Rep: Reputation: 0
Hi!

Thanks for your response. I am actually trying to connect two networks together. The two boxes are just the "routers" to get the two nets talking (as well as being the internet gateway/firewall for each local net). Each site is working fine as a gateway/firewall for their respective nets. I am just trying to route any internal communications between the nets over the VPN.

I think I have all traffic allowed in and out of tun+ on both machines, but I will check in the morning when I get into work.

Mark
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
OpenVPN - Can't ping from server to client side hosts. ycats Linux - Networking 3 09-17-2017 09:19 AM
unable to install centos side by side ubuntu mrajdeep Linux - Newbie 3 08-12-2012 02:21 AM
unable to ping host from OpenVPN client after port 22 denied Winanjaya Linux - Networking 1 03-29-2010 04:34 AM
can't get access to client-side network from server-side network through openvpn nass Linux - Server 1 11-02-2009 04:41 AM
[openvpn] routing at server side Zym0tiC Linux - Networking 2 10-06-2005 03:40 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 10:40 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration