firewall help with lan-to-lan vpn

Posted on 2014-03-11
Last Modified: 2014-03-18
I have another open question related to this issue, but it's kind of got bogged down in the detail of the VPN so I've decided to abandon the question and try to be a little clearer in this one.

Here's the problem:

I have an ipsec tunnel set up and working between two sites, the configuration is nearly correct, but I'm unable to communicate through the tunnel from lan2 to lan1. It is almost certainly a misconfiguration or ommision in the firewall. Here are the details of the network:

LAN1 (left) is
LAN2 (right) is

I can successfully ping the router on the right from a host on the left
I can successfully ping a host on the right from a host on the left
I can successfully ping the router on the left from a host on the right
I cannot ping a host on the left from a host on the right.

This last one's where I'm struggling. I attempt to ping a host on the LAN from the LAN (the ONLY remaining thing that doesn't work) and I can see that my traffic reaches the router on the left (using tcpdump I can see the ICMP requests coming in) but the host on the right receives no reply.

Here's what I've put in my firewall.conf on the left-hand router so far (nb. all traffic across the tunnel uses interface ipsec0 or ipsec1, hence the firewall interface rule):

iptables -A forwarding_rule -i ipsec+ -s -j ACCEPT
iptables -A forwarding_rule -o ipsec+ -d -j ACCEPT

Open in new window

Very very simple, but it does allow almost all the traffic I want. Like I said when the router receives a ping from the right-hand lan it replies no trouble, but doesn't seem to want to relay that message to a host on its local network, OR maybe it isn't passing the local host's reply back across the ipsec interface.

I'm new to iptables, so any and all help is appreciated.
Question by:Joe_Pritchard
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
LVL 34

Expert Comment

by:Duncan Roe
ID: 39922740
forwarding_rule is not a built-in table (is not found in man iptables). Could you post your definition of that table please? Also a link to your old Q might help to give more background - you will have to accept a solution for that Q or deletion of it btw

Expert Comment

ID: 39922956
what's the status of Outside/external interface access rules.

do you have incoming access-rule on each firewall like :

remote lan -- to --- local lan

Accepted Solution

Joe_Pritchard earned 0 total points
ID: 39923074
Hi Folks

Apologies, I hadn't realised about the forwarding_rule table - that's something that openWRT sets up for you.

In any case, I've solved my issue basically through trial and error - I needed to add one more rule:

iptables -A zone_lan_forward -d -j ACCEPT

Again I think zone_lan_forward is one of openWRT's. This solves the problem and traffic is flowing across the tunnel as nature intended.

Thanks for your attention anyway - should I accept my own post as the solution?
LVL 34

Expert Comment

by:Duncan Roe
ID: 39924888
That would be fine with me

Author Closing Comment

ID: 39936360
I solved my issue before anyone really commented with any suggestions, so I'm just closing it as I no longer have a problem...

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
AWS Design\Cisco Meraki 4 43
VPN between Juniper ssg140 (Static IP) to ASA 5500 (Dynamic IP) 23 53
VPN problems 4 89
leap year shell script 10 47
Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question