I ve a gl-inet running with openwrt 18.06.
I ve set up a site2site vpn with openvpn.
vpn server is running on opnsense
I ve no probelem to reach from the openwrt site the other site

network overview


Routenverfolgung zu NAS []
über maximal 30 Hops:

1 <1 ms <1 ms <1 ms GL-AR750 []
2 21 ms 21 ms 21 ms
3 22 ms 21 ms 22 ms NAS []

Ablaufverfolgung beendet.

with ping echo reply it is two way and routing should be fine.
but I can not access the network other way.

ash-4.3# traceroute
traceroute to (, 30 hops max, 60 byte packets
1 ( 0.328 ms 0.281 ms 0.279 ms
2 * * *

I can reach the openvpn interface from the other side
ash-4.3# traceroute
traceroute to (, 30 hops max, 60 byte packets
1 ( 0.315 ms 0.289 ms 0.275 ms
2 ( 21.233 ms 26.276 ms 26.270 ms

i think I have a problem with on the firewall on openwrt.

may be you have a hint for me

This is a question about opensense since that is where the problem is. The router does not have a route to the network because the OpenVPN server did not install one. You should at least see a hop to when tracerouting to 172.131.

Routes from clients to the server LAN are automatic, but to make connections the other way you need a client config directory etc in the OpenVPN server.

I am not sure, but the echo reply finds its way back, that is the reason why I think routing should work.

how can I solve this problem, where I ve to start?

