<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPsec &#x2F; NAT issue]]></title><description><![CDATA[<p dir="auto">Hello all!</p>
<p dir="auto">I have an odd issue that I can't seem to figure out. Right now I have two pfSense boxes connected via an IPsec tunnel:</p>
<p dir="auto">The LAN interface on "gw1" is 10.12.1.254.<br />
The LAN interface on "gw2" is 10.12.9.254.<br />
Both boxes have WAN interfaces connected directly to the Internet, and are performing NAT for their respective LANs.</p>
<p dir="auto">My phase 1 and 2 entries seem correct. Rules on both boxes have been set to allow all traffic to/from the tunnel. A machine within 10.12.1.0/24 can ping a machine within 10.12.9.0/24, and vice versa. This is all normal.</p>
<p dir="auto">The trouble has to do with traffic from other subnets. I have a Nortel switch (ERS5500) at the same site where "gw1" is located. Some of the ports - such as the one which "gw1" is connected to - are assigned to VLAN 10. There are also a few other VLANs, such as VLAN 20, which is 10.12.2.0/24.</p>
<p dir="auto">The Nortel acts as a router among the VLANs and their subnets. Any traffic not bound for one of these subnets (typically Internet-bound traffic) is sent to "gw1". This also seems to work fine.</p>
<p dir="auto">Now that you know the layout, here's the problem. Packets going from 10.12.1.x to 10.12.9.x are routed correctly: source machine, "gw1", "gw2", destination machine. But packets going from other subnets to 10.12.9.x are routed to the Internet: source machine, Nortel, "gw1", and onward to our ISP's router. Oops?</p>
<p dir="auto">I'm wondering why pfSense is sending these packets out to the Internet, rather than through the IPsec tunnel - and what I can do to fix it. Any ideas?</p>
]]></description><link>https://forum.netgate.com/topic/103064/ipsec-nat-issue</link><generator>RSS for Node</generator><lastBuildDate>Sat, 14 Mar 2026 08:24:22 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/103064.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 21 Jul 2016 00:04:27 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IPsec &#x2F; NAT issue on Tue, 02 Aug 2016 17:31:28 GMT]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">Did you create a phase 2 for Othernetwork to 12.9?</p>
]]></description><link>https://forum.netgate.com/post/641496</link><guid isPermaLink="true">https://forum.netgate.com/post/641496</guid><dc:creator><![CDATA[jlevesque]]></dc:creator><pubDate>Tue, 02 Aug 2016 17:31:28 GMT</pubDate></item></channel></rss>