Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Route Between two pfSense boxes

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 2 Posters 556 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      WisceBIat
      last edited by

      This post is deleted!
      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @WisceBIat
        last edited by

        @WisceBIat

        I hope you're not using NAT on box 2. Also, why even have 2 instances of pfSense, when you can simply have 2 subnets on just 1 of them.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • W
          WisceBIat
          last edited by

          I do have NAT setup on box 2 because it's essentially being used to route all Subnet 2 traffic through a VPN. What could I do to keep this current setup, but be able to communicate with hosts on subnet 1?

          JKnottJ 1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @WisceBIat
            last edited by

            @WisceBIat

            Use routing, instead of NAT. You go into System > Routing to do that. You can do it for both IPv4 and IPv6.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • W
              WisceBIat
              last edited by

              Will my VPN keep working if I do this? The setup guide for the VPN told me to do Manual Outbound NAT rule generation on the pfSense 2 box.

              JKnottJ 1 Reply Last reply Reply Quote 0
              • JKnottJ
                JKnott @WisceBIat
                last edited by

                @WisceBIat

                It has no effect on a VPN. Also, you normally don't have a VPN on the same subnet as the LAN. It would have it's own subnet. The exception would be if the VPN used TAP mode.

                This illustrates what the IPv4 address shortage has done. People are so used to using NAT, they think it's the way things are supposed to be done. No, it's a hack to get around the address shortage and often cause problems.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                1 Reply Last reply Reply Quote 0
                • W
                  WisceBIat
                  last edited by

                  The two pfSense boxes can ping ALL of each others' interfaces.
                  But the hosts within each respective Subnet can not be pinged. I think I may have taken a step back in terms of making things work. Here is a new more accurate diagram with some pfsense parameters attached.

                  Untitled.jpg

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.