Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Access from IPSec site to other IPSec site

    Scheduled Pinned Locked Moved IPsec
    5 Posts 2 Posters 474 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • CodeNinjaC
      CodeNinja
      last edited by

      Our main office (Germany) network is managed by pfSense. We connect 1 office in Greece which is managed by an Edgerouter X via IPSec with our office in Germany. We also have some customer networks connected to our office in Germany via IPSec.

      Currently its possible to access all customer sites from our German office. Devices in the Greece office can also access servers and devices in our German office through the IPSec connection. We blocked access from customer sites into our office networks.

      We want that employees in our office in Greece are able to access IPSec site's of our customers but i cant get this working.

      Green arrows means that access is possible in the direction of the arrow (operational)
      Red arrows means that access is blocked in the direction of the arrow (operational)
      Orange arrows describe our goal where this question is about (not working yet)
      88b13c2b-ccbc-4900-8251-8021147dfc3f-image.png

      I created an IPSec firewall rule to allow devices in the greece office to access all networks:
      fe649071-1414-4a3b-b7f2-1e69ac3bf844-image.png

      Do i also need to create custom routes? and if yes, where, in PFSense or at the greece office router?

      1 Reply Last reply Reply Quote 0
      • Z
        Zawi
        last edited by

        Add p2
        example:
        Office Greece <> Customer 1
        Customer 1 <>Office Greece

        CodeNinjaC 3 Replies Last reply Reply Quote 0
        • CodeNinjaC
          CodeNinja @Zawi
          last edited by

          @Zawi
          Thanks, makes totally sence. I did not think about this and will try this at monday and post my findings ;).

          1 Reply Last reply Reply Quote 0
          • CodeNinjaC
            CodeNinja @Zawi
            last edited by

            This post is deleted!
            1 Reply Last reply Reply Quote 0
            • CodeNinjaC
              CodeNinja @Zawi
              last edited by

              @Zawi said in Access from IPSec site to other IPSec site:

              Add p2
              example:
              Office Greece <> Customer 1
              Customer 1 <>Office Greece

              During configuring this, i noticed that this is not what we want as we need to setup a p2 for each costomer-greece office relation. Both, the customer and the greece office are already connected to our main office. We want to "route" the traffic from our greece office to our customer via our main office.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.