Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Ipsec routing from branch to central then internet driving me crazy

    Scheduled Pinned Locked Moved IPsec
    2 Posts 2 Posters 387 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      Hill003
      last edited by

      Hi guys
          recently I just got myself into a situation. I have to establish a site to site ipsec vpn from branch to central office over the internet. lan in branch and central are both using same LAN IP , so I did that BINAT thing. after the ipsec vpn established, both office could communicate each other. However, I was asked to make the branch office accessing the internet only through the central office over ipsec.
          I googled and I found this https://doc.pfsense.org/index.php/Routing_internet_traffic_through_a_site-to-site_IPsec_tunnel#Allow_IPsec_traffic_through_the_firewall
          But now the branch office is still accessing the internet with its WAN interface instead of ipsec. 
          I'm thinking maybe it's the nat rules or routing problems, any hints would be great.

      BRANCH LAN 10.1.0.0/16 WAN 20.1.0.0/16
        CENTRAL LAN 10.1.0.0/16 WAN 30.1.0.0/16
          PFSENSE VERSION: 2.4.2

      The Best

      1 Reply Last reply Reply Quote 0
      • G
        georgeman
        last edited by

        IPsec policies have routing preference over everything on the system (pretty much). If you create a tunnel with destination 0.0.0.0/0, the tunnel goes up and something is misconfigured, I guess you wouldn't get internet access at all instead of getting routed through the regular WAN.

        Post your detailed configuration

        If it ain't broke, you haven't tampered enough with it

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.