Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiple IPSec with same remote subnets

    Scheduled Pinned Locked Moved IPsec
    3 Posts 3 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • cukalC
      cukal
      last edited by

      I'm running multiple IPSec tunnels to various customers providing a SaaS based solution and for each new customer I create an additional vlan, set up the IPSec tunnel and map their network to our dedicated vlan where some services are running. Up until now we've been lucky because they all use different internal network addressing (what are the odds) so the set up is pretty straight forward.

      Next to the regular P1/P2 IPSec tunnel setup I also create a gateway & static route so I can ping from pfSense the remote P2 subnet, not really necessary but easy for some tasks.

      But what do I do when a new client has the same subnet as an existing one?
      Will the P1/P2 take care of the routing or do I need to apply a different configuration somehow?

      Thanks!

      1 Reply Last reply Reply Quote 0
      • dotdashD
        dotdash
        last edited by

        If you control the remote end, binat the incoming p2 to a unique subnet. That being said, if the duplicate remote networks are hitting different internal vlans/subnets, that will work. Static routes are unnecessary with traditional phase2 policy based IPSec. If you need to ping from the firewall itself, select the interface the p2 terminates on as the source.

        1 Reply Last reply Reply Quote 0
        • bepoB
          bepo
          last edited by

          @dotdash is right. If the other side has a matching network they have to configure a nat. Maybe have a look on this page. Its originally posted in german but maybe google translator works:
          https://translate.google.de/translate?hl=de&sl=de&tl=en&u=https%3A%2F%2Fsysadms.de%2F2018%2F09%2Fsite-to-site-ipsec-vpn-bei-gleichen-netzen%2F

          Kind regards

          Please use the thumbs up button if you received a helpful advice. Thank you!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.