Multiple Site to Site and routing

  • Hey everyone,

    I have about 4 site to site VPN IPSec connections setup.

    My main site is cloud hosted using a pfSense 2.4.4 image and connects to my clients' site for remote monitoring and management

    I have a pfSense at my home office that connects to my cloud hosted pfSense.

    What I want to do is to route traffic from my home office to my cloud server then reach my clients' networks.

    Is this possible to do and how?

    I've included a diagram

    Apologies for the duplicate post. I have posted this orginally in the incorrect pfSense forum.


    0_1541539710594_VPN routing.jpg

  • Which kind of VPN is the that one between your home office and the cloud hosted pfSense, is it also an IPSec?

  • LAYER 8 Netgate

    And, What are the existing Phase 2/traffic selector networks between your clients and the central pfSense? How do those relate to everyone.

    You might be able to play some games with NAT but it depends on what is where.

  • @viragomann All site to site VPN connections are using IPSec


    • The p2 network at my home office is 172.16.0/24

    • The p2 network on my cloud pfSense is

  • LAYER 8 Netgate


    So to Client A you have a Phase 2 like this:

    pfSense <-> Client A

    Are the clients averse to you adding more Phase2 networks to their tunnels? Because this would make it work:

    Phase 2 Networks:

    pfSense <-> Client A
    pfSense <-> Client A

    pfSense <-> Home
    pfSense <-> Home

  • No, they are not averse to this.

  • @derelict Just re-reading this.

    Did you mean I should create additional P2 networks between client A and my home device or on the pfSense that is cloud hosted?

  • LAYER 8 Netgate

    Yes. That is one way to do it. The customer sites need to know to send the traffic to your home network via IPsec. Another phase 2 will do that.

  • So if I did this right this is what I did but it is not working.

    The following was added to the customer's pfSense.

    0_1542168612801_Screen Shot 2018-11-10 at 12.09.43 PM.png

    I added this to my Home Office pfSense

    0_1542168832712_Screen Shot 2018-11-10 at 12.07.45 PM.png

    Nothing was added to the Cloud pfSense but no luck.

    Any thoughts?