> Does the gateway has an arp entry for the client? Do you talk about the VPN gateway ? The VPN server is a virtual machine provided by a Cloud Provider, The client is behind a NAT router of my Internet Service Provider.
So I think the VPN gateway does not have an ARP entry for the client. Le sam. 15 nov. 2025 à 16:23, Crystal Kolipe <[email protected]> a écrit : > On Sat, Nov 15, 2025 at 03:56:12PM +0100, Franois RONVAUX wrote: > > > I noticed in the iked.conf on the VPN that the IP address of the client > was > > wrong. > > I fix it and now a route is added when the tunnel is created : > > Destination Gateway Iface > > client_IP VPN_gateway VPN_NIC > > > > But the reply packets are still ot forwarded back to the client. > > In the route, I tried to change the address VPN_gateway by 127.0.0.1 with > > the same result. > > Does the gateway has an arp entry for the client? >

