Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Using pfsense as "Site to Client" VPN Client

    Scheduled Pinned Locked Moved IPsec
    5 Posts 3 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mode
      last edited by

      Hi,

      i do have an end user VPN access to a foreign network. I use the Cisco VPN client on my computer. Works fine.

      Is it possible to establish this connection with pfsense? If yes, would it be possible to do a NAT so that i can access the other site of the VPN from my whole local network with the one IP i got assinged from the foreign network?
      Where to set this up? Just as IPSEC Tunnel? This looks like Site to Site VPN only for me.

      I just do not want to use the local VPN Client when pfsense could to this job too.

      Regards

      mode

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        No, it's not possible currently.

        It may be possible in the future (2.3 or later) but not now or in the next version.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • M
          mode
          last edited by

          Is it possible with any additional software which i may install at the pfsense machine?

          Regards

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            I've hacked vpnc in before for testing purposes. It can be done, but it's far from easy or straight forward.

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              On 2.2 strongswan can handle that, but we don't have options in the GUI to do it. It's capable of pulling an IP and supporting various Cisco Unity features when acting as a client. Not sure if/when that might ever show up, it's not a very common requirement.

              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.