Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Openvpn Site to Site + Roadwarrior

    Scheduled Pinned Locked Moved OpenVPN
    6 Posts 4 Posters 2.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lsk
      last edited by

      Hello everyone,
      My current setup is the following:
      Site to site OpenVPN managed by PFSense
      SITE1:
      Lan subnet: 192.168.0.0/24
      SITE2:
      Lan subnet: 192.168.4.0/24

      Connected via a tunnel 10.0.8.0

      I have a pool of addresses 192.168.2.0 that are used by mobile remote users that connects via SITE1 openVpn server (of course a second one, on the same pfsense box)

      When a remote user connects can see all the machines on the SITE 1 subnet, but cannot access to SITE2 IPs.

      In a similar setup, but with IPSEC for the site to site part, I simply set up a second phase 2 with remote pool as local subnet on SITE1 and as remote subnet on SITE2.

      How to make both subnets accessible at the remote user?

      Thank you in advance

      1 Reply Last reply Reply Quote 0
      • L
        lsk
        last edited by

        A lot of visits and no replies means that doesn't exist a reliable way to do this, or that I cammot explain clearly my issue? English is not my native language so maybe it can be ununderstandable.

        Thank you

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          Just like you have to add another phase 2 in IPsec you have to tell the site-to-site servers about the other networks.

          The Remote Access has to have 192.168.4.0/24 as a local network unless it has redirect gateway set.

          The site-to-site has to have 192.168.2.0/24 set as a local network in the server or as a remote network in the client if using PSK.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • L
            lsk
            last edited by

            But… The site to site is openvpn too and doesn't have phases (as long as I know). The mixed openvpn-ipsec is another setup, in another network that is not connected to this One, that I bought as example of working setup

            1 Reply Last reply Reply Quote 0
            • V
              viragomann
              last edited by

              You have to add sites 2 LAN 192.168.4.0/24 to the "IPv4 Local network(s)" of the roadwarrior settings for pushing this route to the clients.

              1 Reply Last reply Reply Quote 0
              • M
                marvosa
                last edited by

                At a high level:

                • You need to push the Site 2 Lan subnet (192.168.4.0/24) to your clients in the roadwarrior's OpenVPN config

                • You need to add a route for the roadwarrior's tunnel network (192.168.2.0/24) in the Site 2 OpenVPN config

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.