Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [IPSec] VPN with Multi Subnets

    Scheduled Pinned Locked Moved IPsec
    11 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bepoB
      bepo
      last edited by

      Hello,

      are both firewalls pfSense?
      Please show some logs. What is the status on the status page? Especially SAD/SPD page?

      Try to enable "Split connections" in phase 1 configuration.

      Kind regards

      Please use the thumbs up button if you received a helpful advice. Thank you!

      1 Reply Last reply Reply Quote 0
      • R
        rodrigoprazim
        last edited by

        Following the images as requested, as images were after a change of "Split Connections"

        Company 1:
        1_1531318404288_SPD_NJ.PNG 0_1531318404287_SAD_NJ.PNG

        Company 2:
        1_1531318640470_SPD_JM.PNG 0_1531318640470_SAD_JM.PNG

        Thanks for your help.

        Kind regards.

        1 Reply Last reply Reply Quote 0
        • bepoB
          bepo
          last edited by

          @rodrigoprazim said in [IPSec] VPN with Multi Subnets:

          Split Connections

          Is Split Connections enabled on both sides? Did you restarted the ipsec service and reconnected the tunnel?
          The SPD table looks strange.

          Company 1 SPD:
          There is nothing for 172.16.10....

          Company 2 SPD:
          Why the hell is the tunnel endpoint 10.10.0.2 for outbound 172.16.10... network?!

          Maybe restart the hole pfsense on both sides and double check the phase 2 configuration. If nothing helps post the phase 2 configuration screenshots here.

          Please use the thumbs up button if you received a helpful advice. Thank you!

          1 Reply Last reply Reply Quote 0
          • R
            rodrigoprazim
            last edited by

            Thanks for answering. Followed photos as requested.

            Company 1:
            0_1531389109897_Tunnels_NJ.PNG 0_1531389146361_Phase1_NJ_1-2.PNG 0_1531389150880_Phase1_NJ_2-2.PNG

            Company 2:
            0_1531389192342_Tunnels_JM.PNG 0_1531389199958_Phase1_JM_1-2.PNG 0_1531389205686_Phase1_JM_2-2.PNG

            Be remembering, the server was stopped on both sides and then started.

            1 Reply Last reply Reply Quote 0
            • D
              dave.opc
              last edited by

              You have to create 2(two) P2's on both sides
              currently you have only 1 P2 created at Company1 side. Add another P2 with local 172.16.0.0 and remote 172.16.10.0

              R 1 Reply Last reply Reply Quote 0
              • R
                rodrigoprazim
                last edited by

                This post is deleted!
                1 Reply Last reply Reply Quote 0
                • R
                  rodrigoprazim @dave.opc
                  last edited by

                  @dave-opc said in [IPSec] VPN with Multi Subnets:

                  You have to create 2(two) P2's on both sides
                  currently you have only 1 P2 created at Company1 side. Add another P2 with local 172.16.0.0 and remote 172.16.10.0

                  It is not possible, or do not leave system add 2 p2 with the same configuration, already tried this.

                  1 Reply Last reply Reply Quote 0
                  • D
                    dave.opc
                    last edited by

                    It is possible, and it will not be with the same configuration

                    On Company2 you create 1st P2 with local 172.16.0.0 and remote 172.16.10.0 and create 2nd P2 with local 172.16.0.0 and remote 172.16.4.0
                    On Company1 you create 1st P2 with local 172.16.4.0 and remote 172.16.0.0 and create 2nd P2 with local 172.16.10.0 and remote 172.16.0.0

                    R 2 Replies Last reply Reply Quote 1
                    • R
                      rodrigoprazim @dave.opc
                      last edited by

                      @dave-opc said in [IPSec] VPN with Multi Subnets:

                      It is possible, and it will not be with the same configuration

                      I understand what you mean, unfortunately now I can not fiddle with why the VPN is in production, as soon as I do, I'll post it. Thanks for answering.

                      1 Reply Last reply Reply Quote 0
                      • R
                        rodrigoprazim @dave.opc
                        last edited by

                        @dave-opc said in [IPSec] VPN with Multi Subnets:

                        It is possible, and it will not be with the same configuration

                        On Company2 you create 1st P2 with local 172.16.0.0 and remote 172.16.10.0 and create 2nd P2 with local 172.16.0.0 and remote 172.16.4.0
                        On Company1 you create 1st P2 with local 172.16.4.0 and remote 172.16.0.0 and create 2nd P2 with local 172.16.10.0 and remote 172.16.0.0

                        I had tried this, but I was forgetting to change the output interface of Company 1, that is, I was making a faithful copy of the existing P2, a lot of my attention, thank you for helping me.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.