Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Site to Site VPN (Openvpn)

    Scheduled Pinned Locked Moved OpenVPN
    8 Posts 5 Posters 775 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Moon_D
      last edited by

      Could anyone clarify this for me?
      Want to know if I'd need a Public IP Address on both sides when setting up a Site to Site VPN.

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @Moon_D
        last edited by

        For a site-to-site vpn you‘ve to set up a server at one site and a client at the other site.
        If the connection goes across the internet, both sites will have a public address, of course. But I guess, that‘s not that what you’re asking for.
        I think, you will know, if you need a static one. A static IP is only necessary at the server side. Alternatively you can also use a dynamic DNS service with a dynamic address.
        The client establishes the connection to that public server address or to the hostname.

        M 1 Reply Last reply Reply Quote 0
        • JKnottJ
          JKnott
          last edited by

          When you connect to the server, you only need to know it's public address. It helps if it's static or virtually static, as mine is. My host name is static, based on the cable modem and router MACs.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          1 Reply Last reply Reply Quote 0
          • M
            Moon_D @viragomann
            last edited by Moon_D

            @viragomann Sorry if my question wasn't clear enough initially but this was exactly what I was asking for. I have about four sites that are miles apart so yes the connection will go across the internet, so I guess I will need each site to have a static public address if I got you right?

            Or is it possible to just connect the clients to the server without assigning each one a Public IP Address as the Server?

            1 Reply Last reply Reply Quote 0
            • V
              viragomann
              last edited by

              Still not clear, why you're asking that question and what you don't understand here.
              Each device which is connected to the internet has a public IP.
              So since a site-to-site vpn is recommended to be terminated on the edge routers, yes, all vpn endpoints, server and clients, will have public addresses in the strict sense. But only the servers address or hostname has to be static and known by the clients. The clients must only have access to the internet to reach the server. The clients IPs don't matter to establish a vpn connection.
              Fundamentally the clients may also have a private address and access to the internet for connection to the server.

              VPN-sitetomultisite.png

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                OpenVPN is more tolerant of NAT than IPsec.

                The client connects to the server. The client can be behind NAT or whatever.

                The server has to be able to receive client connections. It does not matter if the server address is static or not but it has to be able to receive connections from the internet so it has to either be public or be forwarded from something with a public address.

                If the server address is dynamic then you need a way to communicate what the current address is to the clients. Most people use dynamic DNS for this and tell the clients to connect to the dyndns hostname. I suppose they could always call you and ask what the current IP address is and alter their configuration to connect to that address today instead.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • chpalmerC
                  chpalmer
                  last edited by

                  Its a server client relationship. Only the server side has to have a discoverable address with openvpn.

                  Triggering snowflakes one by one..
                  Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                  1 Reply Last reply Reply Quote 0
                  • M
                    Moon_D
                    last edited by

                    I get it now, thanks, guys!

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.