I have a problem with , I believe , routing on DO Servers.
I manage to connect to servers. One from DO and second from UpCloud with RouterOS on those servers. (I have customized OS on those server to use CHR Mikrotik).
Connected two servers (CHR) with L2TP/IPsec and I have a problem.
Server from UpCloud can ping Mikrotik CHR on DigitalOcean but… Server from DigitalOcean can’t ping Mikrotik CHR on UpCloud
Routing table on Droplet looks strange after adding entry to UpCloud Network where UpCloud Mikrotik is located with all other servers (I have masked public addresses with x)
Destination Gateway Genmask Flags MSS Window irtt Iface
0.0.0.0 xx.xx.xx.xx 0.0.0.0 UG 0 0 0 eth0
10.5.0.0 10.129.9.234 255.255.252.0 UG 0 0 0 eth1
10.14.0.0 0.0.0.0 255.255.0.0 U 0 0 0 eth0
10.129.0.0 0.0.0.0 255.255.0.0 U 0 0 0 eth1
xx.xx.xx.xx 0.0.0.0 255.255.255.0 U 0 0 0 eth0
10.129.9.234 - this is the IP of the DigitalOcean Mikrotik CHR Droplet and 10.5.0.0/22 is network on the other side - the UpCloud Network. ping obviously gave me 100% lost packets but traceroute looks strange
traceroute to 10.5.0.120 (10.5.0.120), 30 hops max, 60 byte packets
1 * * *
2 * * *
3 * * *
4 * * *
5 * * *
6 *
...
30 * * *
10.5.0.120 is the IP of the UpCloud Mikrotik CHR Router There should be on the first hop
I believe there is problem with Routing Table on that Droplet
This textbox defaults to using Markdown to format your answer.
You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!
It’s definitely a routing/firewall issue. What does “ip route show table all” produce? Also, have a peak at some of the “/proc/net/” files with cat. Did you try a tcpdump to see if IPSec routes are actually being applied at run time? Also, what’s your iptables looking like?
DigitalOcean already gave answer for that. It’s impossible. First IP spoofing is enabled so I can add routing between those to providers. Each time when a Server on side B want’s to get to any server through his VPN Gateway Server B to => VPN Gateway Server A (DigitalOcean) and then to the host in the same DataCenter it can’t.
Get paid to write technical tutorials and select a tech-focused charity to receive a matching donation.
Full documentation for every DigitalOcean product.
The Wave has everything you need to know about building a business, from raising funding to marketing your product.
Stay up to date by signing up for DigitalOcean’s Infrastructure as a Newsletter.
New accounts only. By submitting your email you agree to our Privacy Policy
Scale up as you grow — whether you're running one virtual machine or ten thousand.
Sign up and get $200 in credit for your first 60 days with DigitalOcean.*
*This promotional offer applies to new accounts only.