Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSec / NAT Routing question

    Scheduled Pinned Locked Moved IPsec
    5 Posts 3 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • X
      xibalba
      last edited by

      Hi, I was wondering if it was possible to route all of my LAN's NAT'd traffic through an IPSec tunnel.

      Say I have pfSense as a gateway on Network A, and as a gateway on Network B. If I have IPSec tunnel from Network B to A, can I route all of the LAN traffic under Network B (192.168.2/24) through Network A (192.168.1/24) and out the WAN connection of Network A?

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        Try to build a tunnel with a subnet 0.0.0.0/0 at the end where the traffic should leave the internet. Not sure if this works. Haven't used it with such a big netmask yet but already used it to connect several branch offices through the main office to each other by using a bigger subnetmask.

        1 Reply Last reply Reply Quote 0
        • S
          strick1226
          last edited by

          This is something I've been thinking about doing as well, but had no idea where to start.

          Certainly sounds promising.  Would this allow even SMTP traffic from Site A to be routed through Site B's outgoing ISP connection, to allow remote users "local" SMTP access?

          1 Reply Last reply Reply Quote 0
          • H
            hoba
            last edited by

            With that large subnet it should use the pfSense at the other end as default gateway.

            1 Reply Last reply Reply Quote 0
            • S
              strick1226
              last edited by

              So this would require a different class address?

              Sticking with non-routable addresses I couldn't quite figure out how to do something past 192.168.20.0 / 255.0.0.0 …

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.