Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    L2TP/IPSec: How to make split-tunelling work ?

    Scheduled Pinned Locked Moved IPsec
    2 Posts 2 Posters 637 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P Offline
      pude
      last edited by

      Hi guys,

      I've got some issues with my L2TP/IPSec pfsense configuration :

      I don't want all my clients (iOS/Android) traffic to go through the VPN but I can't seem to find how to make that work.

      When "Send all traffic" is enable in iphone VPN's settings, everything is functionnal : LAN adresses + internet (but I access it through the VPN).
      When I disable the "Send all traffic" in iphone's VPN settings, I can connect to the VPN, but can't access LAN or internet anymore.

      2.3.3-RELEASE-p1 (amd64)
      My version of pfsense is the nanoBSD one, running inside a google cloud instance.

      I followed this tutorial to configure the VPN : https://doc.pfsense.org/index.php/L2TP/IPsec minus some firewalling change to only allow access to a specific subnet.
      I can provide more details on configuration, I'm just not sure of which are relevant. Disclaimer : My network skills are not great ;)

      Thanks

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        It's up to the client to decide what to send. There is no mechanism in that protocol to inform the clients what subnets are available. The client has to define that itself.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.