# Aws/oci vpc

**URL:** <https://forum.pritunl.com/t/aws-oci-vpc/1643>\
**Category:** Pritunl VPN\
**Tags:** pritunl-link\
**Created:** [December 20, 2023, 5:57pm UTC](https://forum.pritunl.com/t/aws-oci-vpc/1643 "2023-12-20T17:57:18Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![vni](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/v/48db29/32.png) [@vni](https://forum.pritunl.com/u/vni)\
**Post date:** [December 20, 2023, 5:57pm UTC](https://forum.pritunl.com/t/aws-oci-vpc/1643/1 "2023-12-20T17:57:18Z")

</div>

Good afternoon,  
I need some help, I set up the VPN according to this tutorial: [Site-to-Site with IPsec](https://docs.pritunl.com/docs/pritunl-link)  
With it the link between VPC AWS and OCI is working, however I can’t get access from the AWS servers in the OCI network, on the contrary it works. And the vpn clients can access both networks.

---

<div class="post-metadata">

**Author:** ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)\
**Post date:** [December 22, 2023, 1:25am UTC](https://forum.pritunl.com/t/aws-oci-vpc/1643/2 "2023-12-22T01:25:31Z")

</div>

If only one side isn’t working it is most likely an issue with the Oracle Cloud firewall. You will need to permit all ingress from the Oracle VPC subnet to the Oracle pritunl-link instance. Below is an example of this being done with a Network Security Group policy but it can also be done with a Security List.

 ![Screenshot from 2023-12-21 17-23-48](https://forum-static.pritunl.com/original/1X/28d5924a6bd45cd5ea4ad7cbf2dcea2dbd04e330.png)

---

<div class="post-metadata">

**Author:** ![vni](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/v/48db29/32.png) [@vni](https://forum.pritunl.com/u/vni)\
**Post date:** [December 22, 2023, 1:56pm UTC](https://forum.pritunl.com/t/aws-oci-vpc/1643/3 "2023-12-22T13:56:24Z")

</div>

Worse still, it’s allowed, both in a security list and in the security group. What I’ve noticed is that I can access AWS on the link server in OCI, but not on the rest of the servers, even though I’ve freed the network for the servers.

---

<div class="post-metadata">

**Author:** ![vni](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/v/48db29/32.png) [@vni](https://forum.pritunl.com/u/vni)\
**Post date:** [December 22, 2023, 2:11pm UTC](https://forum.pritunl.com/t/aws-oci-vpc/1643/4 "2023-12-22T14:11:34Z")

</div>

It seems to be a routing problem, because the packet reaches the link server, but can’t find the server I want to reach.  
And the ping command from the link server to the destination server works.

 ![Captura de tela 2023-12-22 110512](https://forum-static.pritunl.com/original/1X/d95b70c4831c374e99886747655c3de58c9191a0.png)

---

<div class="post-metadata">

**Author:** ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)\
**Post date:** [December 22, 2023, 6:39pm UTC](https://forum.pritunl.com/t/aws-oci-vpc/1643/5 "2023-12-22T18:39:50Z")

</div>

Verify that skip destination check is enabled on the VNIC and run the commands below.

```auto
sudo yum -y remove iptables-services
sudo systemctl stop firewalld.service
sudo systemctl disable firewalld.service

```

---

<div class="post-metadata">

**Author:** ![vni](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/v/48db29/32.png) [@vni](https://forum.pritunl.com/u/vni)\
**Post date:** [December 22, 2023, 7:19pm UTC](https://forum.pritunl.com/t/aws-oci-vpc/1643/6 "2023-12-22T19:19:19Z")

</div>

Yes, it’s enabled.  
And my installation is running on ubuntu 22.04.3, I have disabled everything that refers to the firewall.

---

<div class="post-metadata">

**Author:** ![vni](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/v/48db29/32.png) [@vni](https://forum.pritunl.com/u/vni)\
**Post date:** [January 8, 2024, 3:33pm UTC](https://forum.pritunl.com/t/aws-oci-vpc/1643/7 "2024-01-08T15:33:41Z")

</div>

can anyone help?
