<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Mobile IPSEC and BINAT]]></title><description><![CDATA[<p dir="auto">We have a working Mobile IPSEC working on pfSense 2.3.2 but our internal subnet is unfortunately 192.168.1.0/24 so we run into issues and would like to utilize BINAT.</p>
<p dir="auto">This seemed very straight-forward based on the pfSense docs but so far hasn't seemed to have panned out.  We changed our working configuration to just add the BINAT subnet of 192.168.34.0/24 but it doesn't seem to help.</p>
<p dir="auto">We are using the Shrewsoft VPN client (free) and the odd thing we notice is that the route it provides to the client doesn't change.  It feeds it 192.168.1.0/24 not the BINAT subnet.</p>
<p dir="auto">Does anybody have a working Mobile IPSEC configuration using BINAT?</p>
]]></description><link>https://forum.netgate.com/topic/106328/mobile-ipsec-and-binat</link><generator>RSS for Node</generator><lastBuildDate>Sun, 15 Mar 2026 20:09:24 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/106328.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 07 Oct 2016 14:14:36 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Mobile IPSEC and BINAT on Wed, 02 Nov 2016 13:49:11 GMT]]></title><description><![CDATA[<p dir="auto">A few more things we have tried without success…</p>
<ul>
<li>Adding a 1:1 NAT entry for this BINAT (this worked for OpenVPN but not IPSEC)</li>
<li>Changing NAT-T between Force/Auto</li>
</ul>
<p dir="auto">Still no love no matter what.  We have to force add the routes on the Shrewsoft VPN client for the BINAT network and we can see the traffic coming into the IPSEC tunnel but no replies and no traffic hitting the LAN so it seems like NAT is not happening.  No entries in the firewall logs showing that this is blocked either.</p>
]]></description><link>https://forum.netgate.com/post/658510</link><guid isPermaLink="true">https://forum.netgate.com/post/658510</guid><dc:creator><![CDATA[dniesen]]></dc:creator><pubDate>Wed, 02 Nov 2016 13:49:11 GMT</pubDate></item><item><title><![CDATA[Reply to Mobile IPSEC and BINAT on Thu, 13 Oct 2016 13:34:19 GMT]]></title><description><![CDATA[<p dir="auto">Also, we did try flipping the local/BINAT subnets in case they were supposed to be the other way around but it didn't seem to help.</p>
]]></description><link>https://forum.netgate.com/post/654894</link><guid isPermaLink="true">https://forum.netgate.com/post/654894</guid><dc:creator><![CDATA[dniesen]]></dc:creator><pubDate>Thu, 13 Oct 2016 13:34:19 GMT</pubDate></item><item><title><![CDATA[Reply to Mobile IPSEC and BINAT on Tue, 11 Oct 2016 13:30:19 GMT]]></title><description><![CDATA[<p dir="auto">Our local network is set to 192.168.1.0/24 (the actual LAN) and the BINAT is 192.168.34.0/24 (what we would like to translate that subnet to).</p>
]]></description><link>https://forum.netgate.com/post/654492</link><guid isPermaLink="true">https://forum.netgate.com/post/654492</guid><dc:creator><![CDATA[dniesen]]></dc:creator><pubDate>Tue, 11 Oct 2016 13:30:19 GMT</pubDate></item><item><title><![CDATA[Reply to Mobile IPSEC and BINAT on Tue, 11 Oct 2016 07:48:01 GMT]]></title><description><![CDATA[<p dir="auto">What is your local network in the phase 2 set to?</p>
]]></description><link>https://forum.netgate.com/post/654439</link><guid isPermaLink="true">https://forum.netgate.com/post/654439</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Tue, 11 Oct 2016 07:48:01 GMT</pubDate></item><item><title><![CDATA[Reply to Mobile IPSEC and BINAT on Mon, 10 Oct 2016 19:39:24 GMT]]></title><description><![CDATA[<p dir="auto">We tried manually working with 1:1 NAT to get around this as well but still haven't come to a resolution.  I would suspect this is a pretty common configuration so I'm surprised to not find any forum posts about this specific config.</p>
]]></description><link>https://forum.netgate.com/post/654354</link><guid isPermaLink="true">https://forum.netgate.com/post/654354</guid><dc:creator><![CDATA[dniesen]]></dc:creator><pubDate>Mon, 10 Oct 2016 19:39:24 GMT</pubDate></item></channel></rss>