Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Static route via VPN - is this now possible?

    Scheduled Pinned Locked Moved IPsec
    6 Posts 3 Posters 2.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      timboau
      last edited by

      Is it possible to create a static route to another network via VPN in version 2.2.6- I saw an old post linking to monowall that it wasnt (2006) and another post that IPSEC doesnt support routing.

      https://forum.pfsense.org/index.php?topic=25248.0
      https://forum.pfsense.org/index.php?topic=302.0

      I have created static routes (via LAN) pointing to the remote LAN interfaces however running a traceroute from a client machine the route appears to be ignored and the traffic is routed via WAN on the local router.

      Essentially I have remote offices communicating to a datacentre via VPN and all is good - they can communicate to head office individually but I would like to be able to route site to site via the head office.

      All sites running pfsense.

      Is OpenVPN the only solution - and/or are there any guides on site to site configuration using OpenVPN - Ipsec just seems to work so easily!

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        You don't use static routes to route additional networks over IPSec. You use additional Phase 2 entries.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • T
          timboau
          last edited by

          I have approx 25 sites that i wish to route wouldn't that add an insane amount of configuration?

          Is something like this possible with pfsense - or would i be better to use OpenVPN?

          http://blog.servercentral.com/bringing-sanity-to-routing-over-ipsec

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            You can't use static routes with normal tunnel mode IPsec. That link describes using transport mode with GRE and routing across that, which is possible.

            1 Reply Last reply Reply Quote 0
            • T
              timboau
              last edited by

              So.. are we saying that setting up a multisite network with routing via IPSEC is possible (using multiple phase 2 entries) or a combination of GRE as described in the previous link.

              However is this best practice; is there a better way to achieve multisite routing with pfsense that's going to be better to manage/troubleshoot.

              I'm not tied to IPSEC and all ruoters can run pfsense.

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                That GRE method is very interesting to me. First time I have seen it. Are there any MTU issues with it?

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.