[Swan] Tunnel gets established, but machines can reach each other only for less than a minute

Paul Wouters paul at nohats.ca
Fri Feb 3 17:28:05 EET 2023


On Fri, 3 Feb 2023, ud at blueaquan.com wrote:

> Also, an observation I could make is, when the machine at Site Office tries to reach the HO VPN server,
> even though the ping does not happen, I can see the traffic go up incrementally on both sides.  
> However when the HO tries to reach the Site Office, traffic from HO goes out and likewise the In traffic
> at Site Office also goes up incrementally,  but there is no Out traffic from Site Office. Attaching the
> observation FYI.  Any thoughts...?

In that case, perhaps the traffic is just getting filtered. Try logging
all iptables DROP rules and also ensure rp_filter is truly disabled on
all interfaces. And that forwarding is properly allowed.

Paul



More information about the Swan mailing list