<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Siste-to-Site VPN with source NAT]]></title><description><![CDATA[<p dir="auto">Hi there community.</p>
<p dir="auto">Looking for some assistance on getting traffic pass between a pfsense and a Juniper.<br />
The Site-to-Site tunnel is up and running and I was able to ping from one side of the tunnel to the other.<br />
After implementing Source-NAT I am unable to get across the VPN and ping the other site.</p>
<p dir="auto">pfsense Configuration PH1:<br />
Mutual PSK<br />
Mode Main<br />
Preshare Key Preshared<br />
AES128<br />
SHA1<br />
DH group 2<br />
NAT Traversal Auto</p>
<p dir="auto">Configuration PH2:<br />
Tunnel IPv4<br />
Local Net 10.19.20.0/22<br />
NAT/BITNAT 10.3.8.0/22<br />
Remote Net 10.3.8.0/22<br />
AES128<br />
SHA1<br />
PFS off</p>
<p dir="auto">FW Rules<br />
eth2_LAN * * * * none</p>
<p dir="auto">IPsec<br />
eth2_LAN TCP/UDP * 10.3.8.0/22 * * none<br />
eth2_LAN ICMP      * 10.3.8.0/22 * * none<br />
10.3.8.0/22 TCP/UDP * * eth2_LAN * * none<br />
10.3.8.0/22 ICMP * * eth2_LAN * * none</p>
<p dir="auto">NAT Rules:<br />
Outbound: Mode AON<br />
1:1 IPsec 10.3.8.20/22 10.19.20.0/22 *</p>
<p dir="auto">Other side configuration:<br />
PH 1<br />
Remote GW: Host_IP_Address<br />
pre-g2-aes1128-sha</p>
<p dir="auto">PH 2<br />
Tunnel IPv4<br />
nopfs-esp-aes128-sha<br />
Proxy ID Trust-Trust 10.19.20.0/22-10.3.8.0/22</p>
<p dir="auto">I have attached a small diagram for more details.<br />
Thank you in advance for your assistance.<br />
<img src="/public/_imported_attachments_/1/Site-to-Site.png" alt="Site-to-Site.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/Site-to-Site.png_thumb" alt="Site-to-Site.png_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/104762/siste-to-site-vpn-with-source-nat</link><generator>RSS for Node</generator><lastBuildDate>Sun, 19 Apr 2026 23:41:27 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/104762.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 29 Aug 2016 21:17:41 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Siste-to-Site VPN with source NAT on Mon, 27 Feb 2017 16:36:59 GMT]]></title><description><![CDATA[<p dir="auto">I think I have the same issue as you, and figured out the problem and a semi-workaround.</p>
<p dir="auto">Bug/Issue with NAT 1:1 rule operation on IPsec interface<br />
https://forum.pfsense.org/index.php?topic=126289.0</p>
]]></description><link>https://forum.netgate.com/post/682960</link><guid isPermaLink="true">https://forum.netgate.com/post/682960</guid><dc:creator><![CDATA[HunterWare]]></dc:creator><pubDate>Mon, 27 Feb 2017 16:36:59 GMT</pubDate></item><item><title><![CDATA[Reply to Siste-to-Site VPN with source NAT on Wed, 31 Aug 2016 22:22:04 GMT]]></title><description><![CDATA[<p dir="auto">Anyone??</p>
]]></description><link>https://forum.netgate.com/post/647239</link><guid isPermaLink="true">https://forum.netgate.com/post/647239</guid><dc:creator><![CDATA[00Bits11]]></dc:creator><pubDate>Wed, 31 Aug 2016 22:22:04 GMT</pubDate></item></channel></rss>