<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Policy based routing not working for ipsec over openvpn]]></title><description><![CDATA[<p dir="auto">Hi Guys,</p>
<p dir="auto">Needy your help here, I am trying to establish a ipsec tunnel within openvpn but the ipsec response packets do not return from openvpn interface instead it takes the default route defined in pfsense. Below is what I am trying to do.</p>
<p dir="auto">IPsec clients &lt;–IPsec tunnel till PFsense--&gt; openvpn server &lt;----OpenVPN tunnel---&gt; PFsense (openvpn client + IPsec server)</p>
<p dir="auto">Here the IPsec clients are not able to establish the connection with PFsense. The request packets to reach to pfsense on openvpn interface but replies take a different path which is through default gateway, hence it never reaches to clients (or openvpn server). I tried applying policy based routing on openvpn interface with rule as source openvpn network, destination any, gateway openvpn gateway but it did not work. However, if I make the openvpn gateway as default gateway in pfsense then everything works fine, though I cannot do this in production.</p>
<p dir="auto">Please let me know if I am missing something here.</p>
<p dir="auto">Thank you.</p>
]]></description><link>https://forum.netgate.com/topic/115941/policy-based-routing-not-working-for-ipsec-over-openvpn</link><generator>RSS for Node</generator><lastBuildDate>Fri, 12 Jun 2026 14:06:10 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/115941.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 21 May 2017 03:02:30 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Policy based routing not working for ipsec over openvpn on Fri, 26 May 2017 20:23:47 GMT]]></title><description><![CDATA[<p dir="auto">Just to be clear, you just want your mobile IPsec clients to be able to communicate with an endpoint device across an OpenVPN tunnel?  Or is there more to it then that?</p>
]]></description><link>https://forum.netgate.com/post/702183</link><guid isPermaLink="true">https://forum.netgate.com/post/702183</guid><dc:creator><![CDATA[marvosa]]></dc:creator><pubDate>Fri, 26 May 2017 20:23:47 GMT</pubDate></item><item><title><![CDATA[Reply to Policy based routing not working for ipsec over openvpn on Thu, 25 May 2017 07:26:57 GMT]]></title><description><![CDATA[<p dir="auto">Are we 3 on the 2.3.4 version?  Coincidence?</p>
]]></description><link>https://forum.netgate.com/post/701786</link><guid isPermaLink="true">https://forum.netgate.com/post/701786</guid><dc:creator><![CDATA[CuteBoi]]></dc:creator><pubDate>Thu, 25 May 2017 07:26:57 GMT</pubDate></item><item><title><![CDATA[Reply to Policy based routing not working for ipsec over openvpn on Mon, 22 May 2017 10:45:08 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/khsonu">@<bdi>khsonu</bdi></a>:</p>
<blockquote>
<p dir="auto">Hi Guys,</p>
<p dir="auto">Needy your help here, I am trying to establish a ipsec tunnel within openvpn but the ipsec response packets do not return from openvpn interface instead it takes the default route defined in pfsense. Below is what I am trying to do.</p>
<p dir="auto">IPsec clients &lt;–IPsec tunnel till PFsense--&gt; openvpn server &lt;----OpenVPN tunnel---&gt; PFsense (openvpn client + IPsec server)</p>
<p dir="auto">Here the IPsec clients are not able to establish the connection with PFsense. The request packets to reach to pfsense on openvpn interface but replies take a different path which is through default gateway, hence it never reaches to clients (or openvpn server). I tried applying policy based routing on openvpn interface with rule as source openvpn network, destination any, gateway openvpn gateway but it did not work. However, if I make the openvpn gateway as default gateway in pfsense then everything works fine, though I cannot do this in production.</p>
<p dir="auto">Please let me know if I am missing something here.</p>
<p dir="auto">Thank you.</p>
</blockquote>
<p dir="auto">FYI, I have almost the same problem here: https://forum.pfsense.org/index.php?topic=130658.0</p>
<p dir="auto">Would really like to find a solution :)</p>
]]></description><link>https://forum.netgate.com/post/701026</link><guid isPermaLink="true">https://forum.netgate.com/post/701026</guid><dc:creator><![CDATA[kroem]]></dc:creator><pubDate>Mon, 22 May 2017 10:45:08 GMT</pubDate></item></channel></rss>