Site-to-Site VPN between 2 Golds

Comments

5 comments

  • Avatar
    Support Team

    Which site did you use for VPN Server and which site did you use as VPN Client to initiate the site-to-site VPN connection?

    - For now, you should only be able to apply "VPN" on the VPN Client side, not the Server Side. Any device/network on the client side with VPN enabled should be able to access all subnets in the server side. (firewall allow rules are automatically created) The IOT network on the client side should not be able to access the networks in server side.

    - Unless you have setup two site-to-site VPN connections, with each side as VPN Server separated. That's going to make it complicated. Please confirm.

    0
    Comment actions Permalink
  • Avatar
    Larry

    I’ve setup 2 site-to-site connections, each side being a server. I did it this way thinking that by applying the VPN to the LAN devices at each site, only those devices would be able to use the tunnel. The first scenario you mention (one VPN connection from client side) only allowed the LAN devices from accessing the LAN devices on the server side, but the LAN devices from server side couldn’t see the LAN devices on the client side. What’s your suggestion for what I want to do (only the LAN devices should have access to site-to-site tunnel)?

    0
    Comment actions Permalink
  • Avatar
    Support Team

    Here is my suggestion:

    1. Setup a site-to-site connection from site A to site B. (site A as client, and site B as server) You could just turn off the other site-to-site connection from app.

    2. In site A, apply the VPN connection to LAN devices only

    3. In site B, create a blocking rule to block IoT devices from accessing the subnets of site A. (The subnet of site A is the target of the rule, and applied on IoT devices)

    0
    Comment actions Permalink
  • Avatar
    Larry

    I removed both VPN configs and started over. Followed your steps. Right off the bat, the LAN devices on Site B can’t access the LAN devices on site A. Also, with my original config, the OpenVPN and WireGuard clients into Site A could access the LAN devices on Site B. They can’t anymore.

    0
    Comment actions Permalink
  • Avatar
    Support

    Can you please send an email to help@firewalla.com so that we can do further troubleshooting?

    0
    Comment actions Permalink

Please sign in to leave a comment.