Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Need help choosing which vpn platform to use, ipsec/l2tp or openvpn

    Scheduled Pinned Locked Moved Routing and Multi WAN
    17 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RicoR
      Rico LAYER 8 Rebel Alliance
      last edited by

      To have the HQ talking to Remote Sites or vice versa and Remote Site to Remote Site (HQ acting as Hub there) will work with either OpenVPN or IPsec.

      -Rico

      1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by

        Check out this great hangout: https://www.netgate.com/resources/videos/site-to-site-vpns-on-pfsense.html
        I bet this will clear up 99% of your questions. โ˜บ

        -Rico

        1 Reply Last reply Reply Quote 0
        • E
          elementalwindx
          last edited by elementalwindx

          Any idea how?

          I've got HQ and Site A hooked up, but they don't ping each other.

          What I did was in the server side, I didn't put anything in the remote network field.

          If I put the 10.0.1.0/24 subnet in the remote network field, it'll ping just fine. So it seems somewhere I have to enter an IP into the server for each site I add. (I'm trying to avoid that)

          1 Reply Last reply Reply Quote 0
          • RicoR
            Rico LAYER 8 Rebel Alliance
            last edited by

            Yes you need to specify the IPv4 Remote Networks box.
            What is the problem with this? I don't get your point...

            -Rico

            E 1 Reply Last reply Reply Quote 0
            • E
              elementalwindx @Rico
              last edited by elementalwindx

              @Rico

              I'm trying to avoid entering a long string of 50+ remote subnets into the server. There is a possibility this could grow to 100+ sites quickly.

              1 Reply Last reply Reply Quote 0
              • RicoR
                Rico LAYER 8 Rebel Alliance
                last edited by

                Is your typing this slow? ๐Ÿ˜ Entering 50 subnets in one box is like max. 3 minutes. ๐Ÿ˜‚ As johnpoz said this is some one time thing.
                You go with PKI now? You have some more configuration like CSO per Site anyway.
                If you go with shared key you can have only one Site per Server Instance anyway.
                I go with PKI with one Instance per Site to spread the load.
                In short: You can't run any VPN without some administrative work...

                -Rico

                1 Reply Last reply Reply Quote 0
                • E
                  elementalwindx
                  last edited by elementalwindx

                  If I go full mikrotik I get it to work the way I want, but I'm partial to pfsense and it's already in their network.

                  In mikrotik what I do is I setup a normal ipsec/l2tp server, then for each new site I create a secret (basically a client login/password). Inside that secret I can specify a route such as 10.0.1.0/24 172.16.16.5/24 1 (172... is vpn tunnel address) and when the client connects to the vpn server, a route is automatically added to the table of the vpn server, so everyone at HQ knows where 10.0.1.0 is.

                  I'm trying to achieve this same goal in pfsense. It doesn't appear pfsense has this similar secrets section so ipsec doesn't seem to be the way to go in this pfsense/mikrotik combo. Generating a SSL for each new client would be too much of a pain in the butt. Looking for as simple as I can get like described above.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    Again this is not a problem, and takes all of couple of minutes to setup... Did you watch the handout linked to by Rico?

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    E 1 Reply Last reply Reply Quote 0
                    • E
                      elementalwindx @johnpoz
                      last edited by

                      @johnpoz said in Need help choosing which vpn platform to use, ipsec/l2tp or openvpn:

                      Again this is not a problem, and takes all of couple of minutes to setup... Did you watch the handout linked to by Rico?

                      According to that video, I have a hub and spoke design, although I don't need the remote sites to talk to each other so no need for 2+ connections at the remote sites, just one.

                      According to the video it looks like if I use openvpn, I'd have to create an openvpn server for each remote site, or an ssl for each remote site. Definitely don't want to do this.

                      It appears that possibly using mobile ipsec with multiple phase 2's might be the way to go.

                      In the video around 37:00 he talks about defining multiple phase 2 for multiple sites in his non-mobile client ipsec tunnel. So if I went this way, what would be the purpose of specifying the remote server? Also if multiple servers from multiple public ips are connecting to it, how would the remote server field even work?

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by johnpoz

                        Just because you have a hub, ie your HQ doesn't mean your remote (spokes) need to talk to each other through it, or even have to be allowed..

                        You don't need to setup site2site if all you want is remote to log into HQ, but if you want to be able to get to the spokes from hq its much easier to setup site2site. etc..

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.