Multi VLAN routing over IPsec



  • Hi Guys,

    Need help.. long day and I cant find my error…..

    Need to ROUTE multiple VLANS over 1 IPSEC tunnes

    Phase 1 = OK

    Phase 2 = OK for DATA VLAN (LAN) and routes OK between sites....
    Phase 3 = OK for VOICE VLAN (VOICE) but WILL NOT ROUTE!!!!!!!

    FIrewal rules for IPSEC on both boxes are set to ALLOW ANY/ANY for now...

    any ideas ????

    HEAD OFFICE:
    VLAN 1 = DATA  192.168.25.0/24
    VLAN 100 = VOICE = 10.100.25.0/24

    BRANCH OFFICE (REMOTE)
    VLAN 1 = DATA  192.168.26.0/24
    VLAN 110 = VOICE = 10.100.26.0/24

    Pictues of P1 and p2 entries for each site attached


  • Netgate

    Are both phase 2's coming up?



  • yes but  found my error!!!!!  was no creating all P2 necessary.. pic to come soon



  • here's the final setup and working great…. was just to tired... lol




  • I wanted to see if I could get help doing the same idea but for my mobile clients. For example

    Current topology

    Network A 172.16.0.0/24
    Network B 10.0.0.0/24
    Network C 20.0.0.0/24

    I want to grant specific clients access to the specific networks via IPSEC

    Client A P2 Network 0.0.0.0/0 Default route access to all networks
    Client B P2 Network 10.0.0.0/24 Access to Lab A network
    Client C P2 Network 20.0.0.0/24 Access to Lab B network