Score:0

VyOS on AWS EC2, new IPSEC tunnel won't pass traffic- what am I missing

kz flag

This is an existing environment that I just stepped into. Running VyOS as a AWS EC2 instance, which handles all of the site-to-site routing for our company. Everything is already up and working. We just acquired a new company for which I replaced their equipment and allocated their site some address space on our network. I configured the VPN on both ends, and created a new VTI in VyOS with a route to account for the new subnet.

I'm confident the VPN settings are correct (one side is a UDM-Pro, the other side VyOS), the tunnel shows as up on both sides, I'm able to ping WAN interfaces from both ends, however it doesn't want to route/pass the traffic to/from internal networks on either end. I'm pretty sure traffic is getting stuck on the egress from the VyOS in AWS- and I'm pretty sure I just missed something that needs to be configured in AWS- as I have not made any modifications or changes there.

I've looked through the EC2 VPC subnets, route tables, and ACL in/out rules associated with the security group applied to the instance- It looks to me like the new network is accounted for in each of these places... however I am very new to EC2 and don't have a clue where to start looking to troubleshoot this.

Anybody that can point me in a direction for things that I should check in AWS to troubleshoot this?

Score:0
kz flag

Got it sorted, had to add the WAN ip of the new site to the AWS security group that allows inbound traffic to the VyOS instance.

I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.