AWS Site-to-Site VPN ping working, TCP not
I want to establish a site-to-site IPsec VPN connection between an AWS EKS-Kubernetes-Cluster and a server from a different provider using AWS Site-to-Site VPN. Pings get through the VPN, but TCP traffic does not.
The server on the other end runs Ubuntu 20.04 and uses libreswan. The configuration file from AWS for the VPN for openswan has been altered in two ways (that I think should not matter):
auth=esphas been commented out as libreswan would not start otherwise (libreswan 3.29)
- The VPN has been configured to use VTI.
When sending a HTTP request from the AWS site:
tcpdump on the libreswan-site shows SYN arriving and SYN-ACK being sent back while
tcpdump on the EC2-instance (and in a pod as well) only registers SYN.
All incoming traffic has been allowed in security groups and ACLs etc.
I have set up SNAT as recommended here and have confirmed that SNAT works using
traceroute. I think because of SNAT it should not matter anymore that EKS is used in this VPC for this issue.
My guess here is that the non-AWS side of the VPN is doing some sort of NAT. That's a really vague answer but if you're getting one-way communications or odd combinations of things working that's usually the case.
As per your answer: You're using SNAT and (again - a guess) I suspect that is the culprit here.
Advice on creating VPC for EC2 to use IPSec connectionasked 4 months ago
Is it possible to set up a dynamic routing connection to AWS through a site-to-site VPN via a vendor?Accepted Answerasked 2 years ago
Routing to a prefix from TGW through a primary and secondary datacenter VPN connection pathAccepted Answerasked 2 years ago
Conflict between AWS site-to-site VPN (to a VPC) and non-AWS client VPNasked 3 years ago
Working around AWS VPN MTU limitsAccepted Answerasked 2 years ago
AWS Site-to-Site VPN ping working, TCP notasked 18 days ago
Connection to external VPN from Windows Server 2016asked 5 months ago
AWS Site-to-Site VPN ping working, TCP not (EC2 networking details)asked a month ago
Wanted VPN tunnel between elastic ip and on prem static IP?asked 2 months ago
Site to Site IPSec VPN to multiple on-prem firewallsasked 5 months ago