<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Sanity check: site-to-site VPN, with one site behind router?]]></title><description><![CDATA[<p dir="auto">Hi guys,</p>
<p dir="auto">I'm going to have to set up a pfSense VPN from a branch office to the main office.</p>
<p dir="auto">The branch office has an Internet connection that is provided by the landlord and we do not have any access to port forwarding on that router at all.</p>
<p dir="auto">The main office router is a pfSense box.</p>
<p dir="auto">Am I right to say that the IPsec site to site VPN will work? I just need to:</p>
<ul>
<li>
<p dir="auto">Enable NAT traversal</p>
</li>
<li>
<p dir="auto">Not use an IP address as identifier (perhaps use DN as an alternative)</p>
</li>
<li>
<p dir="auto">Have the branch office router establish the connection first (as the main office router wouldn't be able to reach the branch office router anyway</p>
</li>
</ul>
<p dir="auto">and all should be good?</p>
<p dir="auto">Thank you!</p>
]]></description><link>https://forum.netgate.com/topic/101943/sanity-check-site-to-site-vpn-with-one-site-behind-router</link><generator>RSS for Node</generator><lastBuildDate>Sat, 13 Jun 2026 21:19:56 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/101943.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 23 Jun 2016 14:46:28 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Sanity check: site-to-site VPN, with one site behind router? on Mon, 27 Jun 2016 22:19:22 GMT]]></title><description><![CDATA[<p dir="auto">Definitely maybe. Provided thye're not blocking ports. I believe you will want to use "aggressive" and not "main", as it will allow pahse1 IP Address changes.</p>
]]></description><link>https://forum.netgate.com/post/634513</link><guid isPermaLink="true">https://forum.netgate.com/post/634513</guid><dc:creator><![CDATA[jgraham5481]]></dc:creator><pubDate>Mon, 27 Jun 2016 22:19:22 GMT</pubDate></item><item><title><![CDATA[Reply to Sanity check: site-to-site VPN, with one site behind router? on Mon, 27 Jun 2016 22:17:30 GMT]]></title><description><![CDATA[<p dir="auto">That should be good. I've got a few IPSEC tunnels with the same setup as you without issues.</p>
]]></description><link>https://forum.netgate.com/post/634512</link><guid isPermaLink="true">https://forum.netgate.com/post/634512</guid><dc:creator><![CDATA[CobraGT2000]]></dc:creator><pubDate>Mon, 27 Jun 2016 22:17:30 GMT</pubDate></item></channel></rss>