Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSec VPN Using PFSense - Mobile Clients

    IPsec
    2
    2
    4.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jasbuh
      last edited by

      Hi I would like someone to really help me on this, my scenario is like this;

      I have 2 Pfsense Routers running on my network.

      Pfsense1 - 192.168.2.1
      Pfsense2 - 192.168.2.2 - 213.165.180.1 (public)

      Both the routers have a different WAN - ISP Provider. I am trying to set up a VPN over IPSEC connection to only one of the routers which is Pfsense2 - 192.168.2.2. I followed some online tutorials and successfully managed to bring up a tunnel between an external machine and my pfsense router but there is no traffic as in I cannot connect to my network at home to access RDP etc… Can anyone be kind enough to help me on this I've tried every thing, also I have the firewall rule to allow any to any on the IPSec interface, I have set a

      Virtual Address Pool
      Provide a virtual IP address to clients
      Network:  192.168.10.0 /24

      Unticked the option - Network List Provide a list of accessible networks to clients

      Phase 2 - Local subnet set to none.

      I am including screen shots of the setuphttp://www.pixhost.org/show/3739/14253332_capture.jpg

      http://www.pixhost.org/show/3739/14253338_cap2.jpg
      http://www.pixhost.org/show/3739/14253349_gateways.jpg

      Help will be much appreciated and Im even willing to donate to whom helps me. Thanks
      cap2.JPG
      cap2.JPG_thumb
      Capture.JPG
      Capture.JPG_thumb
      gateways.JPG
      gateways.JPG_thumb

      1 Reply Last reply Reply Quote 0
      • B
        bencummins
        last edited by

        Hi

        You need to set the phase2 "Local Network" to the "Lan Subnet" option, and also - leave the tickbox for "Network List  Provide a list of accessible networks to clients" ticked - unless you want ALL traffic from the mobile client to be sent over the tunnel.

        Regards

        Ben

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.