-
toastersonYeah that works. mTLS or Basic Auth
-
extrowerkSo I was still unable to get communication working between the FAR GZ and NEAR GZ. Here is a network-map sketch: paste.omnios.org/?555253e8bd92fa3d#…HVbodwtZiPGMfaJvg9hGVXRYBERZiDSKtSP
-
extrowerkhere is some additional info: paste.omnios.org/?67df501c2b9775cb#…pynVceenBJ8T7xsy4qj7wfLZHS4fUBYMBtw
-
extrowerkI can SSH from any NGZ to the other side's NGZ. I can SSH from any side NGZ to the other side GZ. However I can't SSH from any GZ to the other GZ.
-
extrowerkJust for info: I also can't call the other NGZ from the opposite GZ
-
extrowerkI would greatly appreciate any help.
-
extrowerkI believe the culprit is the routing table at both side GZ-NGZ boundary
-
extrowerkLet me know if you need any additional info
-
m1ariI'm wondering about why you're using addresses in the 100.64/10 range for your tun interface - that seems a little odd.
-
m1ariI don't think you need IPv4 routing enabled in the FAR-NGZ (only Forwarding)
-
m1ariI think you're missing the route for the FAR subnet (10.0.0.0/24) in the Near-GZ routing table.
-
m1ari(unless you've also got some internal NAT going on)
-
m1ariagain I don't think you need IP4 Routing in the Near-NGZ (just Forwarding)
-
m1ariit might be useful to use the -n flag on netstat as well (netstat -nr) so we get numeric networks rather than names
-
m1ariI'm also wondering if you've got any required nat rules (incomming port maps) in place to make the VPN work properly (far end router and near-gz)
-
extrowerkm1ari: 100.64/10 is tailscale-specific thing
-
extrowerkhere is the improved info collection: paste.omnios.org/?449ecdc66d4c339e#…vHkepsNfKJ6r5PpVvhCN7HsnAe9aArowznh