Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SitetoSite VPN Behind Existing Router

    Scheduled Pinned Locked Moved OpenVPN
    14 Posts 3 Posters 1.4k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V Offline
      viragomann
      last edited by

      That's the worse sort of setup. With that there is no correct routing possible, without adding static routes to each LAN device you want to access over the vpn.
      You may do a workaround with outbound NAT to get it work.

      The better solution is to set up a separate network segment between pfSense and the router (maybe a VLAN). So you have only set a static route on the router.

      R 1 Reply Last reply Reply Quote 0
      • R Offline
        rnichols @viragomann
        last edited by

        @viragomann

        Would it be better to give it a port off the router and then run that into the WAN side, then connect the LAN to a switch? Or is that what your suggesting with the network segment.

        Thanks

        1 Reply Last reply Reply Quote 0
        • V Offline
          viragomann
          last edited by

          Let pfSense do the filtering of the whole traffic is always the better way. However, you will need an additional switch to connect your LAN devices.
          If your router has only internal NICs which belong to one switch and does not support VLAN (does it?), there will be no other option.

          Otherwise you can set up something like that:

          Internet ----- router ----- LAN devices
                            |_____ pfSense
          
          R 1 Reply Last reply Reply Quote 0
          • R Offline
            rnichols @viragomann
            last edited by

            @viragomann

            Yes it does VLAN, I have currently 4 vlans that I use.

            Thank you

            1 Reply Last reply Reply Quote 0
            • johnpozJ Offline
              johnpoz LAYER 8 Global Moderator
              last edited by

              Making pfsense a downstream router and then trying to use it as your vpn connections between sites is HARD way to do it, and your going to have issues with asymmetrical routing, or your going to have to source nat or route on your hosts.. And almost always leads to hairpinned connections, etc.

              You can for sure put your pfsense boxes behind another nat router and do it without any issues and simple port forward where the network between your edge router and pfsense... If you can not put your isp router into bridge mode do something like this

              siteAhost
              |
              192.168.2/24
              |
              pfsense
              |
              192.168.1/24 - transit
              |
              A ISP Router
              |
              internet
              |
              B ISP router
              |
              192.168.1/24 - transit
              |
              Pfsense
              |
              192.168.0/24
              |
              SiteBhost

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 25.07 | Lab VMs 2.8, 25.07

              1 Reply Last reply Reply Quote 0
              • V Offline
                viragomann
                last edited by

                So leave pfSense in the physical LAN, configure a VLAN on the router and on pfSense LAN interface. pfSense must not have an address in the LAN subnet.
                Configure the OpenVPN server to listen on LAN, if it is the server.

                If pfSense is not use for other purposes the that set the routers VLAN address as default gateway. Otherwise add a static route for the LAN network pointing to its IP.
                On the router add a static route for the remote network pointing to the pfSense VLAN address.

                1 Reply Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator
                  last edited by johnpoz

                  No.. That is not how you would do it at all.. There is no need for any static routing.. Nor any routing on the edge router (isp device)..

                  The openvpn would listen on pfsense WAN.. Just like it was public.. it would just be rfc1918 address since your edge route is natting. You would have a double nat if you can not have your edge router in bridge mode.

                  The different networks on each site would be listed in your openvpn config.

                  All your clients/networks would be behind pfsense at each site.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 25.07 | Lab VMs 2.8, 25.07

                  R 1 Reply Last reply Reply Quote 0
                  • R Offline
                    rnichols @johnpoz
                    last edited by

                    @johnpoz

                    So you would just plug the thing into the WAN port and let it be? Forward the port 1194 to it and then it would work?

                    Thank you

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ Offline
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      In a nutshell yes.. You just need to make sure that the networks behind pfsense at each site do not overlap.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 25.07 | Lab VMs 2.8, 25.07

                      R 1 Reply Last reply Reply Quote 0
                      • R Offline
                        rnichols @johnpoz
                        last edited by

                        @johnpoz

                        Will it cause issues to have the LAN plugged in as well as the WAN? I have the networks with different IP ranges, the 'tunnel' as a different ip as well.

                        Thank you

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ Offline
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          Huh?? What? Your wan will be connnected to isp router... Your lan will be connected to your lan side switches.. pfsense is now the new gateway for all your lan devices.

                          Yeah your tunnel network can not overlap with your lan networks on either site.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 25.07 | Lab VMs 2.8, 25.07

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.