• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPSEC VPN from HA pfSense to AWS VPC instance not routing

Scheduled Pinned Locked Moved IPsec
4 Posts 3 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • I
    infrapegright.com
    last edited by Oct 26, 2017, 10:29 PM

    I am new to pfSense so forgive my ignorance if my terminology is not correct.

    I have a configured HA pfSense pair running version 2.4.1. This all performs as expected with my internal LANs and DMZs having full access to the internet. I have manually configured NAT for the internal private IP networks and use the CARP WAN VIP as the transfer address.

    I recently established a IPSEC VPN tunnel from the pfSense HA FW to an AWS VPC. Both sides show the VPN as established and UP.

    I have defined the pfSense IPSEC FW rule (file attachment IPSEC FW.png).

    I have updated the AWS route table routes to include rules for Destination = pfsense LAN and target AWS virtual gw.

    I have updated the AWS security groups to allow all inboud traffic from 0.0.0.0/0 and the AWS VPC default security group. The outbound traffic is wide open with all traffic destined for 0.0.0.0/0

    It does not appear that traffic from my pfSense configuration is routing to the VPN and likewise on the AWS.

    Any help is greatly appreciated for this novice user.

    ![IPSEC FW.PNG](/public/imported_attachments/1/IPSEC FW.PNG)
    ![IPSEC FW.PNG_thumb](/public/imported_attachments/1/IPSEC FW.PNG_thumb)

    1 Reply Last reply Reply Quote 0
    • I
      infrapegright.com
      last edited by Oct 27, 2017, 4:06 PM

      Problem resolved. I forgot to setup the static routing on the AWS VPN connection itself.

      1 Reply Last reply Reply Quote 0
      • U
        ultralite
        last edited by Mar 13, 2018, 10:34 AM

        Hello,
        I have the same problem here.

        Do you use static route for the VPN connection between pfsense instance and the VPC?

        1 Reply Last reply Reply Quote 0
        • D
          Derelict LAYER 8 Netgate
          last edited by Mar 13, 2018, 10:44 AM

          You need to route the correct traffic from the VPC to the VGW in AWS.

          Traffic from the pfSense side is sent to the VPN according to the traffic selectors (phase 2 networks).

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received