Page 1 of 2 12 LastLast
Results 1 to 10 of 11
  1. #1
    Newbie
    Join Date
    Oct 2011
    Posts
    10

    Default resources inacessible : mode routing or bridging ?

    Hello,

    I installed and configured openvpn to the site to site. The vpn is mounted and I can ping the IP address of a machine's site A site from a machine B. However, I can not ping with the hostname or the FQDN.

    A LAN <=> untangle (route) <=> internet <=> untangle (route) <=> LAN B

    I have read and applied all that I see in the wiki and the forum but nothing works.

    I want to know what mode openvpn site to site to install there? bridging or routing? I feel that it is in route! But the broadcast does not routing? Maybe this the problem? How to change the mode? in terminal ...

    Can anyone help me? Should we add a rule in the FW to pass traffic on port 1194? and / or should we add a conditional forwarding in our internal DNS server that redirects to the domain name of the remote site? Nowhere is mentioned to do that but maybe he should do it anyway?

    I thank you

  2. #2
    some dude hlarsen's Avatar
    Join Date
    Jul 2010
    Location
    sfba
    Posts
    1,323

    Default

    if you can ping/access resources by IP, the tunnel works. have you tried this?

    http://wiki.untangle.com/index.php/O...site_tunnel.3F
    Attention: Support on the Untangle Forums is provided by volunteers and community members.
    If you need official Untangle support please call or email support@untangle.com.

  3. #3
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,976

    Default

    Site to Site VPN does nothing magic when it comes to DNS. So if you want the clients on the far side of the tunnel to use a DNS server in your main network, you need to configure the local DHCP server to pass out the appropriate DNS server information.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    NexgenAppliances.com
    Phone: 866-794-8879

  4. #4
    Newbie
    Join Date
    Oct 2011
    Posts
    10

    Default

    hlarsen thanks but yes i have tried this yet.

  5. #5
    Newbie
    Join Date
    Oct 2011
    Posts
    10

    Default

    Quote Originally Posted by sky-knight View Post
    Site to Site VPN does nothing magic when it comes to DNS. So if you want the clients on the far side of the tunnel to use a DNS server in your main network, you need to configure the local DHCP server to pass out the appropriate DNS server information.
    this step is not mentionned in the wiki ! i don't understand vey well ! how to do this ?

  6. #6
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,976

    Default

    Yes it is mentioned in the wiki, and the specifics of "how to" are dependent on your network. Configuration of a DHCP service on another device is outside the scope of the Untangle forums.

    If you have Untangle operating as the DHCP server on that remote network, we need a pile more detail about your configuration to assist you.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    NexgenAppliances.com
    Phone: 866-794-8879

  7. #7
    Newbie
    Join Date
    Oct 2011
    Posts
    10

    Default

    I am not sure of any understanding.

    In fact on each of the remote sites, I already have a DNS server and DHCP. what did you need other information such as? I have a DMZ in the site B.

    one question: openvpn with untangle mode site to site let it go broascast arp requests? I think not because it is the routing mode is used? Can you confirm this?

    thank you
    Last edited by hello_kitty; 10-08-2011 at 01:44 PM.

  8. #8
    Newbie
    Join Date
    Oct 2011
    Posts
    10

    Default

    here is what I have in the Active Routes for each site in Untangle. See files attached

    I find it strange the first line for site B. What do you think?


    And when I do a tracert, I find it strange response

    Site A: I go through a VPN interface not present in the routing table!
    site B, I go through the interface that I find strange above

    I do not understand anything and it comes in addition to resolve names !!!
    Attached Images Attached Images
    Last edited by hello_kitty; 10-08-2011 at 02:10 PM.

  9. #9
    Master Untangler
    Join Date
    Dec 2010
    Location
    Echuca, Victoria, Australia
    Posts
    258

    Default

    This is all correct.

    What the others were trying to say, was what are you using for dns at each site? Are you using Untangle, or a Microsoft Server for DNS.

    What you will need to do, is in either one, go through manually adding dns entrys for the servers you require at the other site.

  10. #10
    Newbie
    Join Date
    Oct 2011
    Posts
    10

    Default

    in each site, i use a windows DNS Server. In the site A, it is windows 2003 DNS server ands in the site B it is a windows 2008 DNS server. The domain name in each site is different.

    To try, I added in the dns seveur of my site A, a forwarder for the domain name of the site B with the LAN IP address of the DNS server of the site B. The same goes for site B. But it made no difference to my problem. I still can not ping a machine using its domain name on the remote site. I do not understand.

    Should I change the rules in Packer Filter ? Should I add rules in the firewall for DNS traffic ?

    I followed this tutorial and the link inside
    http://forums.untangle.com/openvpn/8...tructions.html

    do I restart untangle each amended to take into account changes?

    Thanks
    Last edited by hello_kitty; 10-09-2011 at 06:58 AM.

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2