Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfsense routing help needed

    Scheduled Pinned Locked Moved General pfSense Questions
    pfsense
    8 Posts 5 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      vishal.gajjar
      last edited by

      We have two different datacenters, I have one pfsense firewall on location A (US) with local ip: 192.168.100.0/24 & Live ip: 31.21.105.2/27 and other one pfsense firewall on location B (UK) with local ip: 192.168.20.0/24 Live ip: 141.51.106.50/27. Additionally, I have IPsec tunnel between both the pfsense.

      Now I want to shut down my server except Pfsense on location A (US) and shift the vms from Location A to Location B. But I want to keep my in/out traffic via Location A (US) firewall only. How can I route the traffic of all the VMs from Location B pfsense to Location A pfsense. So that if any request comes on LocationA pfsense it will redirect the traffic to vms behind Location B Pfsense and same for the outgoing traffic should be redirected from Location B pfsense to Location A pfsense.

      Thanks in Advance
      Vishal Gajjar

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        What sort of bandwidth do you require? It may not be possible to do that via IPSec.

        Are you going to move the 192.168.100.0/24 subnet to the UK side? Or put the US VMs in 20.0/24?

        Steve

        V 1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by johnpoz

          Even if you have all the bandwidth in the world and ipsec overhead was no big deal... The added latency is going to be HORRIBLE..

          What if in the UK... You want a user to hit your US IP, have the traffic go all the way back over to the UK over your vpn and then then back again to the US and then Back again to the UK..

          Seems like HORRIBLE ideal - unless you have some fix for the laws of physicals and latency ;)

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • M
            msf2000
            last edited by

            Are you trying to failover from one datacenter to the other? I.e., is everything "production" in one datacenter? Or are both datacenters "production"/"live"?

            1 Reply Last reply Reply Quote 0
            • V
              vishal.gajjar @stephenw10
              last edited by

              @stephenw10

              We will be only moving VMs in 20.0/24. for one week, so we can re-structure 100.0/24. That's the motive.

              Even we want to make it work like in/out traffic should go via the US only.

              Thanks

              1 Reply Last reply Reply Quote 0
              • N
                netblues
                last edited by netblues

                So, lets say you rent another host in the same uk dc for a week, ask the dc to move the ip to that host, do the restructure and move back.
                Much less of a hassle, to say the least.

                1 Reply Last reply Reply Quote 0
                • V
                  vishal.gajjar
                  last edited by

                  @msf2000
                  No, we are not trying to failover, we want to re-structure our data center, so for a few days, we want to move and want to route in/out traffic via the US.

                  Thanks

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Mmm, I would think there are better ways to do this. But if you wanted to do it like this you will need to setup an OpenVPN tunnel between the two sites to route traffic across, you can't route over IPSec for this. You will need the OpenVPN interfaces assigned at least at the UK end to get reply-to states on traffic coming across the tunnel. Then:
                    Move the VMs to the 192.168.20.0/24 subnet in the UK. That may well be non-trivial!
                    Change your port forwards in the US firewall to point to the new internal IPs.
                    Add policy routing rules on the UK firewall to route traffic from those VM out via the US if that is required for traffic initiated by the VMs.
                    Add outbound NAT rules on the US side for the 20.0/24 subnet to allo that traffic out.

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.