Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN Traffic Rule

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 3 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      fuzion1
      last edited by

      Hello,

      I have a VPN setup with IPsec from a server outside a network with pfsense to our sonicwall. The VPN works great, and is connected just fine.  Anyways, there is a problem where i cannot see the network that the pfsense is on.  I have a rule setup that disallows all traffic, but i have my rules setup to allow traffic.  What rule do i need to setup to allow my network behind the sonicwall see the network with the pfsense on it?

      1 Reply Last reply Reply Quote 0
      • Cry HavokC Offline
        Cry Havok
        last edited by

        One that allows it - before the default block.

        If you're uncertain, posting a screenshot of the IPsec interface's rules will allow others to see what's wrong (assuming you provide the IP range that you're using for IPsec and the LAN).

        1 Reply Last reply Reply Quote 0
        • F Offline
          fuzion1
          last edited by

          Everything works fine if i just block all TCP connections, but i want to block All connections by default.  I cannot figure out what i am missing to allow it through.  Maybe you can take a look at the rules here, and see if i am missing one.

          pfsense.gif
          pfsense.gif_thumb
          pfsense1.gif
          pfsense1.gif_thumb

          1 Reply Last reply Reply Quote 0
          • jimpJ Offline
            jimp Rebel Alliance Developer Netgate
            last edited by

            The only rules that matter to the IPsec tunnel are on the IPsec tab, and there you have an allow all rule.

            What exactly is it that you are trying to accomplish? You're contradicting yourself saying you want to block all connections and still "see" the remote network. You have to allow something or the far side of that tunnel will never be able to get back into the network behind pfSense.

            What do you need to be able to do that you can't do with the rules you have?

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.