Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Trying to Understand how can I access the main netowrks from a downstream networks

    Scheduled Pinned Locked Moved Firewalling
    12 Posts 2 Posters 1.0k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • X Offline
      xlameee @xlameee
      last edited by

      @xlameee ANYONE

      1 Reply Last reply Reply Quote 0
      • johnpozJ Offline
        johnpoz LAYER 8 Global Moderator
        last edited by

        Can you draw this up please, then I would be happy to help.

        This vpn is a site to site?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07 | Lab VMs 2.8, 25.07

        1 Reply Last reply Reply Quote 0
        • X Offline
          xlameee
          last edited by

          I have an idea, but I am not sure that this is the best way to go!!!!

          What if I create an other VLAN let say VLAN141 and then BRIDGE that VLAN to "STORAGE (OPT2 int) (VLAN 70)" on my main pfsense box and then from vmware (Where windows server is installed) I add an 2nd interface on VLAN141 port group and add a static IP without gateway so it won't confuse Bill Gates :)

          Would this solve my problem

          1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by johnpoz

            No bridging is not the answer!

            Draw this up - I have read over your post a few times and just not clicking how you have this stuff connected.. Where is this main box - some other site?

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07 | Lab VMs 2.8, 25.07

            X 1 Reply Last reply Reply Quote 0
            • X Offline
              xlameee @johnpoz
              last edited by

              @johnpoz No the mainbox is on the same site with the down stream and Yes it is a site-to-site VPN

              1 Reply Last reply Reply Quote 0
              • johnpozJ Offline
                johnpoz LAYER 8 Global Moderator
                last edited by johnpoz

                So breakout some crayons or whatever and put it on paper ;) So we can see what networks are where.. If its same site - why are you connected via a vpn?

                you have a downstream network at site A, and then this other site B that is connect to A via vpn can not get to the downstream networks at site A?

                If you have downstream at A, where is the routing and transit network shown?

                You have this?

                youhavethis.png

                What can not talk to what? Adjust to how you have it setup if need be, and put in your networks, etc. But a downstream network needs to be connected via a transit or you will run into asymmetrical routing issues. Or you have to do host routing, or you have to nat the downstream, etc.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07 | Lab VMs 2.8, 25.07

                1 Reply Last reply Reply Quote 0
                • X Offline
                  xlameee
                  last edited by xlameee

                  I did my best
                  2019-10-10_6-21-45.jpg

                  OFFICE SITE 1 is the VPN site-to-site server all other are clients each of the clients have to go to the server first before go anywhere else

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Offline
                    johnpoz LAYER 8 Global Moderator
                    last edited by johnpoz

                    Ok that is a start.. Where are the networks.. You call it a downstream switch.. So its doing routing? If so how is it connected. Where is the transit? What are the networks your VMs are connected to?

                    Is that core switch also a L3 doing routing?

                    Why are you doing a site to site vpn for that pfsense located at site 1?

                    And then you have another pfsense VM that is also connected via vpn - and it has a network(s) behind it? That windows server for example?

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07 | Lab VMs 2.8, 25.07

                    X 1 Reply Last reply Reply Quote 0
                    • X Offline
                      xlameee @johnpoz
                      last edited by xlameee

                      @johnpoz sorry those 2 switches are not connected
                      2019-10-10_6-30-10.jpg

                      None of the switches are routing they are L3 switches but not routing. PFSENSE is the router DNS DHCP and so on

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Offline
                        johnpoz LAYER 8 Global Moderator
                        last edited by johnpoz

                        Huh? They sure look like there connected to the esxi host to me ;) So your pfsense vm is the one doing the routing.. Again why is it on a vpn if its located in site 1?

                        What is the point of the main box pfsense? If there is nothing behind it you need to get to?

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07 | Lab VMs 2.8, 25.07

                        X 1 Reply Last reply Reply Quote 0
                        • X Offline
                          xlameee @johnpoz
                          last edited by xlameee

                          @johnpoz there is a lots of stuff behind the main box one of them is freenas all I need to do is this windows server 2016 to have access to and freenas smb shred storage without going trough the VPN server to office site 1 and back

                          ANY IDEA

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.