Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSEC VPN between Juniper and PFsense

    Scheduled Pinned Locked Moved IPsec
    5 Posts 2 Posters 10.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      alam3
      last edited by

      Hello:
      I have established an ipsec vpn tunnel between my pfsense and a third party's juniper device.  I have followed the steps outlined in the PFsense book and reviewed the steps outlined in http://doc.pfsense.org/index.php/VPN_Capability_IPsec walk through.
      The tunnel is up; however, no traffic can pass.  I have setup an IPSEC firewall rule which allows all traffic from the third party site.
      The one deviation from the book/walk through is that the third party requires the Local Host on my side be set to my WAN public IP address and they do not support the use of internal IP addresses for remote subnets on their side.

      I was hoping someone could shed some insight into what the problem might be.

      Thank you.

      1 Reply Last reply Reply Quote 0
      • C
        cmb
        last edited by

        You can't use the public IPs on your side because IPsec applies before NAT, it'll only match the policy for traffic initiated by the firewall itself in that case. The usual work around there, though not ideal, is to do NAT on one system and do the IPsec on another.

        1 Reply Last reply Reply Quote 0
        • A
          alam3
          last edited by

          @CMB  Thank you for replying.  When you say do ipsec on one system and nat on another do you mean pfsense system?

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            Yes

            1 Reply Last reply Reply Quote 0
            • A
              alam3
              last edited by

              @CMB  Ok.  I have created a new pfsense device strictly for vpn.  I recreated the ipsec config and pointed the local subnet to my external ip address.  I have created only one rule in the Rules\IPSEC (see below).  Is this what you were thinking?

              Proto      Source      Port    Destination    Port    Gateway
              TCP          *            *      192.168.1.11    *        *

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.