Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Muliple VPN configuration help

    Scheduled Pinned Locked Moved General pfSense Questions
    12 Posts 3 Posters 1.1k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jnewman33 @jake
      last edited by

      @jake Thanks for the reply. I had assumed that since the PCs were seeing both networks that the IPsec was working properly. Are you saying that minus the USG weirdness my laptops should be able to access all resources already given this configuration?

      J 1 Reply Last reply Reply Quote 0
      • J Offline
        jake @jnewman33
        last edited by

        @jnewman33 Just so I understand. If a "road warrior" connects to the USG firewall they cannot access the pfSense network?

        J 1 Reply Last reply Reply Quote 1
        • J Offline
          jnewman33 @jake
          last edited by

          @jake That is correct. Also have the problem the other way around as well. I would be happy if I could just get the "road warrior" wireguard VPN to see the Ubiquiti side.

          J 1 Reply Last reply Reply Quote 0
          • J Offline
            jake @jnewman33
            last edited by

            @jnewman33 I'm more familiar with OpenVPN but I'd assume you'd need to push the routes for the remote network to the wireguard client or if it's routed then setup the routes to be accessible to wireguard.

            J 2 Replies Last reply Reply Quote 1
            • J Offline
              jnewman33 @jake
              last edited by

              @jake Thanks for your continued help here. I may abandon the wireguard for now and switch to OpenVPN into pfsense for now. I was excited to the get the wireguard working but its unique interface is beyond what I can manage without someone like Christian's help.

              1 Reply Last reply Reply Quote 0
              • J Offline
                jnewman33 @jake
                last edited by

                @jake I have now created an OpenVPN connection for remote access to pfsense. I believe that now I need to push routes and maybe create rules in order to see the other side of my IPsec tunnel? Would you have any guidence here ?

                1 Reply Last reply Reply Quote 0
                • stephenw10S Offline
                  stephenw10 Netgate Administrator
                  last edited by

                  I assume you are using policy based IPSec between the two sites?

                  If so you need to have policies in place to cover the traffic from the road warrior tunnel subnets in addition to the two local LANs.

                  Steve

                  J 1 Reply Last reply Reply Quote 0
                  • J Offline
                    jnewman33 @stephenw10
                    last edited by jnewman33

                    @stephenw10-

                    Thanks for replying. I have simplified my diagram a bit:
                    VPN 1 (2).jpeg

                    To simplify matters I am no just using OpenVPN into pfsense. That VPN works and is providing access to pfsense resources as expected.

                    I am assuming the site-to-site is policy based but I am confused as how to configure the addition of the OpenVPN subnet (10.10.50.0/24).

                    Appreciate any help you can provide.

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S Offline
                      stephenw10 Netgate Administrator
                      last edited by

                      OK so in order for OpenVPN users to access resources in the 10.10.33.0/24 subnet the IPSec tunnel needs to have a Phase2 policy configured for 10.10.20.0/24 to 10.10.33.0/24.

                      You probably only have one P2 policy defined and it will be for 10.10.34.0/24 to 10.10.33.0/24 so traffic from the OpenVPN is not carried.

                      What is you current IPSec config?

                      Steve

                      J 1 Reply Last reply Reply Quote 1
                      • J Offline
                        jnewman33 @stephenw10
                        last edited by

                        @stephenw10

                        Thanks for your help here. I actually had created a second P2 but had created it backwards. Fixed that up and now all works.

                        Thanks again,
                        James

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.