IpSec problem after upgrade to 7.0.x

Hello.
We are using Omnia Turris OS 6.5.2 and have configured IpSec for VPN to internal network.
After automatic upgrade to 7.0.0 and also manual to next 7.0.1 and 7.0.2 releases, VPN stopped working. So we had to rollback to previous snapshot.

After upgrade we are able to connect, but no server in LAN can be accessed. It seems like routing problem. There are slightly different settings for routing in 7.0.x LuCi interface and I did not found any differences comparing 6.5.2 to 7.0.x settings.
IpSec is configured through VPN interface using IpSec device.
Had anybody have this kind of problem? Or can anybody help me with configuration? What could be the reason?

Thank you all

Post your firewall config. In whichnzone is this ipsec interface? Probabbly missing forwarding between zones

I can’t check settings on latest version as our VPN is not working and we are working remotely, but this is config of 6.5.2 and I checked this on 7.0.2 and it was the same

Yeah but is the logical interface of your ipset in vpn_turris zone? Its in network interfaces tab

it seems to be, This is how it is in 6.5.2 version. As far as I remember, when I checked it after last try, it was the same in 7.0.2, but it not works as it works in 6.5.2.
obrázok

Owww try ticking the masquerading check box and reload firewall. I have it checked in my firewall config but using OpenVPN from turris. And it works

Thank you Orest.
Currently it is false. I will try set ti up next week when onsite on updated version. I will let you know.

Anyway, it is interesting that we have this issue after upgrade to 7.0.0.

I may check locally. To disable that and see if I can reach some internal hosts from VPN without masq.

Edit: i just checked and with masq=0 it also works. So I leave it off. If I were you I would try to ping a host in your local network and check route there and also check if ipsec tunnel adds route to your internal hosts networks.

So its most likely not a problem with masquerading sorry for wrong input.

1 Like