6.12.8 - Need help with site to site VPN


Recommended Posts

Basically I want to have a site/LAN to site/LAN VPN setup so that I can do offsite backups and easily access my parents LAN from my LAN.

 

Setup is as follows:

Site A:
Router: PFsense or opnsense (currently have both setup for testing but not running simultaneously) running as VM (currently unraid, formerly proxmox) with PCI-E passthrough for WAN and LAN NICs.
VPN Server: Unraid

IP subnet: 192.168.0.0/24

 

Site B:
Router: Asus RT-AC68U running latest merlin firmware
VPN Server: Unraid

IP Subnet: 192.168.1.0/24

 

I have tried both Wireguard via unraid and currently trying Tailscale using the unraid plugin but I keep getting disconnection issues when I try to do anything when accessing Site B from Site A, this includes running VNC/Windows RDC (will run for a couple of minutes) and I'm unable to do any SMB file transfers (but I can successfully access the SMB share to browse) and can access web UIs.

Site B to Site A seems perfectly fine though and using my mobile I have no issues either.

 

On site A I have upnp enabled with a gateway/route setup for 192.168.1.0 and on site B I also have upnp setup as well as a static route for 192.168.0.0.

 

I also tried reducing the MTU to 1420 when I was on Wireguard, but this didn't fix the issue and broke access to the Asus router webui using wireguard.

 

I don't seem to have other issues with the networks, for example, Chrome Remote Desktop to site B runs fine and I can do local LAN file transfers as well as download files from the internet without issue.

 

Any suggestions for where/what I can try?

Thank you

Link to comment
3 hours ago, tech3475 said:

Any suggestions for where/what I can try?

Move the VPN duties to the router? I know what you are trying to do should be possible, but it seems to me that it would be better to put the VPN on the endpoints since you want LAN to LAN vs. device to device.

Link to comment
5 minutes ago, JonathanM said:

Move the VPN duties to the router? I know what you are trying to do should be possible, but it seems to me that it would be better to put the VPN on the endpoints since you want LAN to LAN vs. device to device.

 

I had tried that in the past but I couldn't get it to work properly between the two different routers, which was one reason I gave up and just went with WG/unraid.

Link to comment

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.