Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Admin access via ipsec

    Scheduled Pinned Locked Moved IPsec
    4 Posts 2 Posters 513 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      fundikompyuta
      last edited by

      I am setting up a wide area network using pfsense routers, connected together with ipsec. I am new to pfsense but have done similar jobs with other routers previously.

      At the moment I can connect to the GUI interface of a remote pfsense router only via a node on the remote network.

      It seems that by default admin access to the router is restricted to nodes on networks directly connected to a LAN interface on the router. Is there a way of allowing admin access directly to the router from remote private networks connected by ipsec?.

      The manual suggests allowing remote access via VPN but doesn't give any details of how to do it. It may mean you should use VPN to access the GUI via another node on a local network as I am currently doing but this is not ideal when the remote network consists entirely of specialist equipment. I would really like to to be able to access the remote pfsense directly without going via another node on its local network.

      Any assistance would be very welcome. Please let me know if I should provide any details of the existing configuration.

      M 1 Reply Last reply Reply Quote 0
      • M
        mcury @fundikompyuta
        last edited by

        @fundikompyuta You can connect directly to the LAN interface IP address of the remote pfsense if that LAN network is included in the P2 of the IPsec tunnel.

        Check if you have an allow rule at the local site, allowing your IP address to connect to the remote site, to the remote pfSense's LAN IP address, TCP port 80/443.

        Also, check if the remote site has an allow rule in IPsec firewall rule tab.
        This tab is for incoming connections for the tunnel.

        dead on arrival, nowhere to be found.

        F 2 Replies Last reply Reply Quote 1
        • F
          fundikompyuta @mcury
          last edited by

          Thanks very much @mcury - you are saying I should be able to connect so I will check the various rules again.

          1 Reply Last reply Reply Quote 0
          • F
            fundikompyuta @mcury
            last edited by

            @mcury It was a missing firewall rule - now working fine.

            1 Reply Last reply Reply Quote 1
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.