Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN Client - Connect to Site to Site VPN

    Scheduled Pinned Locked Moved IPsec
    6 Posts 5 Posters 753 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      stephen21
      last edited by

      Hello

      PFsense Version - 2.4.5-RELEASE-p1 (amd64)

      We have various PFsense installs, providing a very good and reliable, Site to Site solution.

      We also use the equally good and reliable, Greenbow VPN Client to provide remote access to one of the Sites.

      I am looking for suggestions as to how I can reconfigure the Site A PFSense to allow the a remote VPN client, to access other sites (Site B), over the site to site VPN connections

      See attached / Below

      Existing Config:-
      Site.jpg

      Required Config:-
      The Remote VPN to have access to Site B while connected to Site A

      Suggestions appreciated

      Thank you

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @stephen21
        last edited by

        @stephen21
        In the remote VPN settings on A add the site B networks to the "Local Networks".

        At B add the remote access tunnel network to the "Remote Networks".

        Care that the access is allowed in firewall rules.

        S 1 Reply Last reply Reply Quote 0
        • S
          stephen21 @viragomann
          last edited by

          @viragomann said in VPN Client - Connect to Site to Site VPN:

          @stephen21
          In the remote VPN settings on A add the site B networks to the "Local Networks".

          At B add the remote access tunnel network to the "Remote Networks".

          Care that the access is allowed in firewall rules.

          Hi
          Thanks for your suggestion, but these settings are already made otherwise site to site access would not be possible..

          My problem is to allow the Remote Client to have access to both Site A and Site B, while only connected to Site A

          Thank you

          bingo600B 1 Reply Last reply Reply Quote 0
          • N
            NOCling
            last edited by

            Your Network IP concept is not good, you can not route straight Site A - Site B.
            Use a second P2 with 192.168.150.x or change the IP for mobile Clients to 192.168.(2/3/4).x and use 192.168.0.0/22 to route in P2.

            Netgate 6100 & Netgate 2100

            1 Reply Last reply Reply Quote 0
            • M
              milew
              last edited by milew

              I think the firewall is the problem. Show us what rules you have set on the IPSec interface in location A and B. Note that the source is 192.168.150.x.
              What masks do the IP address pools have?

              1 Reply Last reply Reply Quote 0
              • bingo600B
                bingo600 @stephen21
                last edited by

                @stephen21 said in VPN Client - Connect to Site to Site VPN:

                @viragomann said in VPN Client - Connect to Site to Site VPN:

                @stephen21
                In the remote VPN settings on A add the site B networks to the "Local Networks".

                At B add the remote access tunnel network to the "Remote Networks".

                Care that the access is allowed in firewall rules.

                Hi
                Thanks for your suggestion, but these settings are already made otherwise site to site access would not be possible..

                My problem is to allow the Remote Client to have access to both Site A and Site B, while only connected to Site A

                Thank you

                Your Site A <--> Site B VPN would work fine without Site B knowing about the "Dial-in" VPN Lan.

                But Site B , would not know how to route packets back to the "Dial-in" VPN clients (via Site A) , unless you have done as @viragomann says.

                /Bingo

                If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                pfSense+ 23.05.1 (ZFS)

                QOTOM-Q355G4 Quad Lan.
                CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.