Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SitetoSite VPN Behind Existing Router

    Scheduled Pinned Locked Moved OpenVPN
    14 Posts 3 Posters 1.4k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      rnichols @viragomann
      last edited by

      @viragomann

      The second one , pfsense as a lan device.

      Thank you

      1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann
        last edited by

        That's the worse sort of setup. With that there is no correct routing possible, without adding static routes to each LAN device you want to access over the vpn.
        You may do a workaround with outbound NAT to get it work.

        The better solution is to set up a separate network segment between pfSense and the router (maybe a VLAN). So you have only set a static route on the router.

        R 1 Reply Last reply Reply Quote 0
        • R Offline
          rnichols @viragomann
          last edited by

          @viragomann

          Would it be better to give it a port off the router and then run that into the WAN side, then connect the LAN to a switch? Or is that what your suggesting with the network segment.

          Thanks

          1 Reply Last reply Reply Quote 0
          • V Offline
            viragomann
            last edited by

            Let pfSense do the filtering of the whole traffic is always the better way. However, you will need an additional switch to connect your LAN devices.
            If your router has only internal NICs which belong to one switch and does not support VLAN (does it?), there will be no other option.

            Otherwise you can set up something like that:

            Internet ----- router ----- LAN devices
                              |_____ pfSense
            
            R 1 Reply Last reply Reply Quote 0
            • R Offline
              rnichols @viragomann
              last edited by

              @viragomann

              Yes it does VLAN, I have currently 4 vlans that I use.

              Thank you

              1 Reply Last reply Reply Quote 0
              • johnpozJ Offline
                johnpoz LAYER 8 Global Moderator
                last edited by

                Making pfsense a downstream router and then trying to use it as your vpn connections between sites is HARD way to do it, and your going to have issues with asymmetrical routing, or your going to have to source nat or route on your hosts.. And almost always leads to hairpinned connections, etc.

                You can for sure put your pfsense boxes behind another nat router and do it without any issues and simple port forward where the network between your edge router and pfsense... If you can not put your isp router into bridge mode do something like this

                siteAhost
                |
                192.168.2/24
                |
                pfsense
                |
                192.168.1/24 - transit
                |
                A ISP Router
                |
                internet
                |
                B ISP router
                |
                192.168.1/24 - transit
                |
                Pfsense
                |
                192.168.0/24
                |
                SiteBhost

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07 | Lab VMs 2.8, 25.07

                1 Reply Last reply Reply Quote 0
                • V Offline
                  viragomann
                  last edited by

                  So leave pfSense in the physical LAN, configure a VLAN on the router and on pfSense LAN interface. pfSense must not have an address in the LAN subnet.
                  Configure the OpenVPN server to listen on LAN, if it is the server.

                  If pfSense is not use for other purposes the that set the routers VLAN address as default gateway. Otherwise add a static route for the LAN network pointing to its IP.
                  On the router add a static route for the remote network pointing to the pfSense VLAN address.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Offline
                    johnpoz LAYER 8 Global Moderator
                    last edited by johnpoz

                    No.. That is not how you would do it at all.. There is no need for any static routing.. Nor any routing on the edge router (isp device)..

                    The openvpn would listen on pfsense WAN.. Just like it was public.. it would just be rfc1918 address since your edge route is natting. You would have a double nat if you can not have your edge router in bridge mode.

                    The different networks on each site would be listed in your openvpn config.

                    All your clients/networks would be behind pfsense at each site.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07 | Lab VMs 2.8, 25.07

                    R 1 Reply Last reply Reply Quote 0
                    • R Offline
                      rnichols @johnpoz
                      last edited by

                      @johnpoz

                      So you would just plug the thing into the WAN port and let it be? Forward the port 1194 to it and then it would work?

                      Thank you

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Offline
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        In a nutshell yes.. You just need to make sure that the networks behind pfsense at each site do not overlap.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07 | Lab VMs 2.8, 25.07

                        R 1 Reply Last reply Reply Quote 0
                        • R Offline
                          rnichols @johnpoz
                          last edited by

                          @johnpoz

                          Will it cause issues to have the LAN plugged in as well as the WAN? I have the networks with different IP ranges, the 'tunnel' as a different ip as well.

                          Thank you

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ Offline
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            Huh?? What? Your wan will be connnected to isp router... Your lan will be connected to your lan side switches.. pfsense is now the new gateway for all your lan devices.

                            Yeah your tunnel network can not overlap with your lan networks on either site.

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 25.07 | Lab VMs 2.8, 25.07

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.