Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Use Public IP site A for server on site B

    Scheduled Pinned Locked Moved NAT
    5 Posts 2 Posters 313 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lio1503
      last edited by

      Hi everyone

      I'm looking for a solution to use my additional public ip on site A to reach a server on site B.
      Both site are connected via openvpn site to site and everything work.But when I make a NAT between the public IP on site A and server on site B it doesnt work.

      Thanks in advance.

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @lio1503
        last edited by

        @lio1503
        At site B you have to assign an interface to the respective OpenVPN instance, if you haven't done this already.

        Then move over the firewall rule for passing the traffic to this new interface.

        Ensure that there is no pass rule on the OpenVPN tab, which matches the forwarded traffic!

        L 2 Replies Last reply Reply Quote 0
        • L
          lio1503 @viragomann
          last edited by

          @viragomann

          Thanks for the reply.
          I do this but its doesnt work.
          You can see the config on images.

          Firewall on site A

          NAT
          nat_pfsenseA.jpg

          RULES WAN TAB
          RULE_WAN_pfsenseA.jpg

          RULES OPENVPN TAB
          RULE_OPENVPN_pfsenseA.jpg

          Firewall on site B

          INTERFACE OPENVPN
          interface_pfsenseB.jpg

          RULES OPENVPN INTERFACE TAB
          RULE_OPENVPN_interface_pfsenseB.jpg

          RULES OPENVPN TAB
          RULE_OPENVPN_TAB_pfsenseB.jpg

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @lio1503
            last edited by

            @lio1503
            Are you sure, that the destination server allows access from outside of it's subnet?

            On pfSense you can investigate the traffic flow with Diagnostic > Packet Capture.
            At site B sniff the traffic on the internal interface and check if you can see the forwarded packets and responses from the server.

            1 Reply Last reply Reply Quote 0
            • L
              lio1503 @viragomann
              last edited by

              @viragomann

              Thanks for your help.Its work now.
              In fact its was my openvpn interface that not handle ip address.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.