Ipsec to main site with two the same remote subnets

  • per subject is this possible ?
    main site
    remote subnet currently connected
    new subnet that we want to join which can't be modified

    would this cause any issues ?


  • Rebel Alliance Developer Netgate

    NAT must be done on the site with the conflict. If you cannot change the new router you are connecting with, then you'll have to renumber or NAT your other conflicting site.

  • Hello,

    I have the exact same situation here at the moment.

    I have a PfSense router at our main office. And we have Draytek routers at our remote offices. Wee need to monitor the servers/ switches and other network devices in the remote office.

    Some of our remote offices have the same subnet e.g.

    Is there a way to make this work? (like NAT over IPsec?)

    Hope someone can help me out.

    Kind regards,


  • Rebel Alliance Developer Netgate


    Some of our remote offices have the same subnet e.g.

    You can work around this with NAT on IPsec Phase 2 entries. Your situation is different than the one the OP of this thread has, please start a new thread.

  • Thanks for your reply jimp.

    I will start a new thread.

Log in to reply