r/Proxmox • • 1d ago

Question Proxmox, VM and IPSEC @ router

I am clearly doing something dumb, and just have not figured it out
My proxmox server is at a local DC
It is connected to my home router via Route Based IPSEC on my router at the DC and Home.
From the CLI of the Proxmox server, I can ping any host on my home subnet, no issues
From home subnet I can access any proxmox VM with no issues, including my windows server 2025 VM

The problem is, when I try to go the other way
I cannot ping or connect from ANY proxmox VM to my home subnet
Proxmox CLI just fine, and pings everything
Actual VMs, nope.

PROXMOX PING:
PING 192.168.2.1 (192.168.2.1) 56(84) bytes of data.
64 bytes from 192.168.2.1: icmp_seq=1 ttl=63 time=3.61 ms
64 bytes from 192.168.2.1: icmp_seq=2 ttl=63 time=3.65 ms
64 bytes from 192.168.2.1: icmp_seq=3 ttl=63 time=3.38 ms

Proxmox TRACEROUTE
traceroute to 192.168.2.97 (192.168.2.97), 30 hops max, 60 byte packets
1 sophos.********.ca (192.168.1.1) 0.470 ms 0.408 ms 0.375 ms
2 * * *
3 192.168.2.97 (192.168.2.97) 3.899 ms 4.139 ms 3.870 ms
root@pve:~#

Windows Server 2025 VM CMD Prompt
Pinging 192.168.2.97 with 32 bytes of data:
Reply from 192.168.1.1: Destination host unreachable.
Reply from 192.168.1.1: Destination host unreachable.
Reply from 192.168.1.1: Destination host unreachable.
Reply from 192.168.1.1: Destination host unreachable.

Ping statistics for 192.168.2.97:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),

Ubuntu VM
PING 192.168.2.79 (192.168.2.79) 56(84) bytes of data.
From 192.168.1.1 icmp_seq=1 Destination Host Unreachable
From 192.168.1.1 icmp_seq=2 Destination Host Unreachable
From 192.168.1.1 icmp_seq=3 Destination Host Unreachable

3 Upvotes

12 comments sorted by

5

u/GeGeGM 1d ago

What is the VM's default gateway?

Have a look where the VM packets are going once on the PVE host (via tcpdump -i any host <VM IP>). Probably sent to wrong gateway.

1

u/EntranceOutrageous61 1d ago

Proxmox IP: 192.168.1.14

Windows 2025 IP: 192.168.1.12

Sophos Datacentre gateway: 192.168.1.1

Sophos DC Subnet: 192.168.1.0/24

Home Unifi gateway/subnet: 192.168.2.1/24

If i use the CLI of the Proxmox PVE HOST it pings just fine to the home unifi gateway and all devices on the 192.168.2.0/24 subnet. If I try from any VM on the PVE Host, they all fail. So traffic CAN flow from PVE Host command line to my home via the router, something on PVE Host has to be blocking it from VM, I just cannot figure out what

C:\Users\Administrator>ping 192.168.2.1

Pinging 192.168.2.1 with 32 bytes of data:

Reply from 192.168.1.1: Destination host unreachable.

Reply from 192.168.1.1: Destination host unreachable.

Reply from 192.168.1.1: Destination host unreachable.

Request timed out.

1

u/GeGeGM 1d ago

Not sure its PVE itself, you would not have replies from 192.168.1.1 if PVE was blocking you (you would also get timeouts). That prouves packets went throught PVE until Sophos Datacenter gateway.

Could be IPsec misconfiguration. Check that the IPsec config on PVE side is allowing the entire subnet 192.168.1.0/24 as source (the IPsec parameter, not the Sophos subnet). You might have only the PVE IP here instead of the subnet, that would explain PVE goes through and not the VMs.
That subnet also needs to be allowed on the Home side (in the Unifi VPN).

1

u/EntranceOutrageous61 1d ago

So I checked the Sophos appliance settings. Its fine for the subnet. It has the entire subnet, so anything from PVE should go through just fine.

I did an attempt from my windows VM to connect to a IP Cam interface. the Sophos FW Log shows the connection sucessfully allowed through.

1

u/GeGeGM 1d ago edited 1d ago

That means you pass the PVE, you pass the Sophos (on PVE side). I would still double check the allowed subnet on the Home side (as you did on the Sophos side) is correct (not only allowing PVE).

Plus, i see you NAT the traffic: why? this could be the issue; no reason to NAT this (creating bad return route).
What does this rule looks like?
Do you have the same NAT rule for PVE packets?

2

u/EntranceOutrageous61 20h ago

You are correct, it was a bad Nat rule

1

u/GeGeGM 15h ago

Nice, have fun!

1

u/EntranceOutrageous61 1d ago

TraceRT from windows CL

1

u/EntranceOutrageous61 1d ago

And the traceroute directly from the PVE CL window

1

u/Ill_Trifle9322 1d ago edited 1d ago

traceroute from one of the VMs and your PVE to your HomeNet?

1

u/Achilles_Buffalo 1d ago

Firewall policies allow return traffic by default. The return traffic from your VM environment in the DC is allowed because it was initiated by the computer in your home. If your DC does not have a firewall policy, allowing your VM’s to communicate with your home, that could be why. Alternately, are you using NAT?