VPN

EdgeRouter: IPsec tunnel to FRITZ!Box 7390

3 minute read Modified:

Why an IPsec tunnel?

Previously I used a tinc tunnel between me and my parents’ server. This situation was not ideal because my parents’ server had to be the gateway for some things to be able to use them via the tunnel, while the FRITZ!Box was the real gateway. Since I wanted to replace my gateway with an EdgeRouter Lite, I used this to setup an IPsec tunnel with the FRITZ!Box.

tinc: Network is unreachable

1 minute read Modified:

The problem

When the Fedora 20 server at my parents rebooted because of a general power failure, the tinc tunnel between my parents and myself didn’t work anymore.

Troubleshooting

I enabled the debug logging by sending an INT signal to the daemon.

tincd -n ubbink -k INT

This resulted in the following log items (journalctl -f -l –unit tincd@ubbink.service):

tinc.ubbink[9707]: Got INT signal
tinc.ubbink[9707]: Temporarily setting debug level to 5.  Kill me with SIGINT again to go back to level 0.
tinc.ubbink[9707]: Trying to connect to amys (xxx.xxx.xxx.xxx port 655)
tinc.ubbink[9707]: xxx.xxx.xxx.xxx port 655: Network is unreachable
tinc.ubbink[9707]: Could not set up a meta connection to amys
tinc.ubbink[9707]: Trying to re-establish outgoing connection in 35 seconds
tinc.ubbink[9707]: Purging unreachable nodes

I couldn’t find why this was happening because when I used netcat to connect to port 655 via udp everything worked.

nc -vu xxx.xxx.xxx.xxx 655
Also a telnet to port 655 worked, but why wasn’t tinc able to make the connection?

Recent posts
- full list -