Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Trying to Understand how can I access the main netowrks from a downstream networks

    Scheduled Pinned Locked Moved Firewalling
    12 Posts 2 Posters 1.0k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ Offline
      johnpoz LAYER 8 Global Moderator
      last edited by

      Can you draw this up please, then I would be happy to help.

      This vpn is a site to site?

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 25.07 | Lab VMs 2.8, 25.07

      1 Reply Last reply Reply Quote 0
      • X Offline
        xlameee
        last edited by

        I have an idea, but I am not sure that this is the best way to go!!!!

        What if I create an other VLAN let say VLAN141 and then BRIDGE that VLAN to "STORAGE (OPT2 int) (VLAN 70)" on my main pfsense box and then from vmware (Where windows server is installed) I add an 2nd interface on VLAN141 port group and add a static IP without gateway so it won't confuse Bill Gates :)

        Would this solve my problem

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator
          last edited by johnpoz

          No bridging is not the answer!

          Draw this up - I have read over your post a few times and just not clicking how you have this stuff connected.. Where is this main box - some other site?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 25.07 | Lab VMs 2.8, 25.07

          X 1 Reply Last reply Reply Quote 0
          • X Offline
            xlameee @johnpoz
            last edited by

            @johnpoz No the mainbox is on the same site with the down stream and Yes it is a site-to-site VPN

            1 Reply Last reply Reply Quote 0
            • johnpozJ Offline
              johnpoz LAYER 8 Global Moderator
              last edited by johnpoz

              So breakout some crayons or whatever and put it on paper ;) So we can see what networks are where.. If its same site - why are you connected via a vpn?

              you have a downstream network at site A, and then this other site B that is connect to A via vpn can not get to the downstream networks at site A?

              If you have downstream at A, where is the routing and transit network shown?

              You have this?

              youhavethis.png

              What can not talk to what? Adjust to how you have it setup if need be, and put in your networks, etc. But a downstream network needs to be connected via a transit or you will run into asymmetrical routing issues. Or you have to do host routing, or you have to nat the downstream, etc.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 25.07 | Lab VMs 2.8, 25.07

              1 Reply Last reply Reply Quote 0
              • X Offline
                xlameee
                last edited by xlameee

                I did my best
                2019-10-10_6-21-45.jpg

                OFFICE SITE 1 is the VPN site-to-site server all other are clients each of the clients have to go to the server first before go anywhere else

                1 Reply Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator
                  last edited by johnpoz

                  Ok that is a start.. Where are the networks.. You call it a downstream switch.. So its doing routing? If so how is it connected. Where is the transit? What are the networks your VMs are connected to?

                  Is that core switch also a L3 doing routing?

                  Why are you doing a site to site vpn for that pfsense located at site 1?

                  And then you have another pfsense VM that is also connected via vpn - and it has a network(s) behind it? That windows server for example?

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 25.07 | Lab VMs 2.8, 25.07

                  X 1 Reply Last reply Reply Quote 0
                  • X Offline
                    xlameee @johnpoz
                    last edited by xlameee

                    @johnpoz sorry those 2 switches are not connected
                    2019-10-10_6-30-10.jpg

                    None of the switches are routing they are L3 switches but not routing. PFSENSE is the router DNS DHCP and so on

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ Offline
                      johnpoz LAYER 8 Global Moderator
                      last edited by johnpoz

                      Huh? They sure look like there connected to the esxi host to me ;) So your pfsense vm is the one doing the routing.. Again why is it on a vpn if its located in site 1?

                      What is the point of the main box pfsense? If there is nothing behind it you need to get to?

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 25.07 | Lab VMs 2.8, 25.07

                      X 1 Reply Last reply Reply Quote 0
                      • X Offline
                        xlameee @johnpoz
                        last edited by xlameee

                        @johnpoz there is a lots of stuff behind the main box one of them is freenas all I need to do is this windows server 2016 to have access to and freenas smb shred storage without going trough the VPN server to office site 1 and back

                        ANY IDEA

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.