Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSEC > Routing traffic from A Site to C Site through B site

    Scheduled Pinned Locked Moved IPsec
    5 Posts 2 Posters 389 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      DiegoEspinozaP
      last edited by DiegoEspinozaP

      Dear Community,

      I hope that whoever reads this post is doing fine,
      About this topic, i would like to know if someone has created the following environment, or knows something about it.

      Multiple A sites communicates with a single host in B site.

      Now i need to use B site as an intermediary between A sites and C site.
      So any traffic between A will flow to C site through B site, and viceversa

      Any ideas will be greatly appreciated
      Warm Regards

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @DiegoEspinozaP
        last edited by

        @DiegoEspinozaP said in IPSEC > Routing traffic from A Site to C Site through B site:

        Multiple A sites communicates with a single host in B site.

        Are these site to site IPSec?
        If so, policy-based or routed?

        D 1 Reply Last reply Reply Quote 0
        • D
          DiegoEspinozaP @viragomann
          last edited by

          @viragomann Hi there,
          So... i have many IPSEC A sites and hosts that send traffic to a single host in IPSEC B site.
          And those are IPSEC tunnels.
          Should i try with routed vti s2s?

          Warm Regards

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @DiegoEspinozaP
            last edited by

            @DiegoEspinozaP
            No, you can also go with policy-based, but it's relevant for how to set it up. In routed IPSec you can just add static routes to route the traffic properly.
            If you're using tunnels you have to add a phase 2 for A-C to both connections.

            This means in the A-B IPSec at A:
            local: A subnets
            remote: C subnets
            In B-C at B you have to do the same.

            And at B in A-B and at C in B-C:
            local: C subnets
            remote: A subnets

            D 1 Reply Last reply Reply Quote 0
            • D
              DiegoEspinozaP @viragomann
              last edited by

              @viragomann Hi!
              Thanks a lot, ill try and let you know the result

              Warm Regards

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.