Multiple Mobile Users with subnets?



  • Hi,

    my situation is like this:

    • pfSense with fixed IP is the VPN hub. External address 1.2.3.4, internal subnet 10.0.0.0/24
    • Multiple IPSEC capable routers (bintec be.IP plus) need to connect from DYNAMIC external addresses
    • They might not even have a real external address, but connect through another router with NAT
    • Each router represents a subnet on its internal interface, e.g. 10.0.1.0/24, 10.0.2.0/24 and so forth
    • IKEv1 Main Mode with PSK is used

    I am not able to use the standard mobile users config, because it does not allow me to specify the subnets for each peer. Or am I doing something wrong?

    I cannot change the network topology, the subnets are fixed.

    Is there a way to do this without having to use dyndns names for the peers? That's what I'm doing now, but it requires some dirty hacking for peers that don't know their real external address (I'm using my own dyndns service).

    I was using a standard Linux VM with strongSwan before, and it was no issue to have multiple peers with "right=%any" if they all shared the same PSK. The differentiation was done based on the IDs, I guess.

    Help is greatly appreciated, I can provide more details if needed.

    Thanks in advance!
    Karsten