Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Hub & Multi-Spoke VPN - allow communication between spokes?

    Scheduled Pinned Locked Moved IPsec
    5 Posts 5 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      whitewidow
      last edited by

      I currently have a hub and spoke ipsec vpn set up with communication working only from each spoke to the hub not the other spokes. I would like to have the spokes communicate with each other with out destroying the current configuration and moving to a mesh (tinc) but id be open to some feedback on the benefits of tinc over my current configuration so maybe in the future I will migrate to that.

      I have read that adding another phase 2 to the spoke I wish to communicate with then repeat that on the other spoke will accomplish this but I have been unsuccessful getting that to work. Do I need to add another phase 2 to the each spoke in the hub as well? I have 7 spokes and it seems like to get them to communicate will be a lot of phase 2 entries…

      Here is my current vpn

      Hub
      10.0.1.0/24

      Spokes
      10.0.2-8.0/24

      Let me know if what I want to accomplish with what I have set up is feasible.

      1 Reply Last reply Reply Quote 0
      • G
        georgeman
        last edited by

        Since you cannot create static routes over IPsec, you need to add Phase2 entries linking the remote and local subnets, on every spoke.

        Yes, they will be a lot. If you want full connectivity you will need 8 Phase2's on each spoke.

        Best regards!

        If it ain't broke, you haven't tampered enough with it

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          OpenVPN makes it easier.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • J
            jcpolo
            last edited by

            @Derelict:

            OpenVPN makes it easier.

            Do you have an example of this setup or some kind of a guide? I've been trying to get my open vpn setup this way but cannot get more than 1 site to connect to the server successfully.

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              https://doc.pfsense.org/index.php/OpenVPN_Site-to-Site_PKI_%28SSL%29

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.