Start With Reachability and Addressing
A site-to-site VPN depends on both gateways being reachable and on the networks behind each site being routable without conflicts. Overlapping LAN subnets are a common reason a tunnel cannot route traffic correctly.
Check the Fundamentals
- Both WAN connections are online and stable.
- Peer/public address information is current.
- Local networks at each site do not overlap.
- Authentication/keys and tunnel settings match.
- Required routes are present.
- Upstream NAT or carrier-grade NAT is considered where relevant.
Tunnel Up but Traffic Fails?
If the tunnel reports connected but traffic does not pass, check routes, firewall rules, source/destination networks and whether the traffic is actually using the intended gateway.
VPN issues are often well suited to remote support because the configuration can be reviewed without an on-site visit.