LDAP over IPSEC VPN
-
I have a site A and a site B both have a pfSense router and they are connected by a IPSEC VPN tunnel. From site A I can ping every device at site B and from site B I can ping every device at site A.
At site B I have a MS AD and I have setup a LDAP authentication server with no problem. But when I want to setup a LDAP authentication server on the pfSense at site A and use the IP address of the MS AD server at site B there seems to be no connection.
Does anybody know what I am missing here? Maybe an extra firewall rule?
-
Traffic from the firewall itself won't use the IPsec tunnel unless it matches the IPsec P2. Since IPsec is not routed, the firewall does not know well enough on its own that it needs to source the traffic in a special way in order to use the tunnel.
https://doc.pfsense.org/index.php/Why_can%27t_I_query_SNMP,_use_syslog,_NTP,_or_other_services_initiated_by_the_firewall_itself_over_IPsec_VPN