Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Feature Request- Need multiple Subnets (vpn selectors)

    Scheduled Pinned Locked Moved IPsec
    9 Posts 6 Posters 4.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      blacklotus
      last edited by

      i often set up vpn's between sites with multiple subnets behind the firewall, often to seperate voip traffic. as far as i  know there is no way to have multiple subnets on each or any side of a pfsense ipsec vpn. most non SOHO vpn gateways will allow this, adtran, cisco, astaro etc.

      you can't always create multiple vpn's between sites. many firewalls won't allow it so interoperability goes out the door.
      does anyone know if this is going to be allowed in future versions or if its even possible now? i'm sure that its probably possible in the underlying code just that the gui doesn't allow for it, right>?

      Adtran

      Astaro

      AdtranVPN.jpg
      AdtranVPN.jpg_thumb
      AstaroVPN.jpg
      AstaroVPN.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • K
        ktims
        last edited by

        Can you not add static routes for the networks in question with the remote endpoint as the gateway?

        1 Reply Last reply Reply Quote 0
        • B
          blacklotus
          last edited by

          @ktims:

          Can you not add static routes for the networks in question with the remote endpoint as the gateway?

          but that wouldn't be vpn

          1 Reply Last reply Reply Quote 0
          • K
            ktims
            last edited by

            I meant to use the remote LAN gateway (192.168.5.1 or whatever), which will still tunnel all the traffic over the VPN. Now that I think about it though I'm not sure it'd even work with the way pfSense does routing over IPsec. Either way, what you're asking for is indeed a slightly different and useful feature.

            1 Reply Last reply Reply Quote 0
            • L
              luma
              last edited by

              I think it's possible to configure multiple subnet in the future pfSense 2.0 platform.

              Please see : http://devwiki.pfsense.org/v20Todo

              Regards

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                Multiple subnets w/IPSec are possible in 1.2.x in a non-obvious way, and there are some issues, but you can try it to see if it works for you:

                http://doc.pfsense.org/index.php/IPSec_with_Multiple_Subnets

                It didn't work for me, but I think that was mainly due to the fact that I was using a mobile tunnel and not a static site-to-site tunnel. The parts of my VPN that needed multiple subnets got moved to an OpenVPN tunnel and have been working happily ever since.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • B
                  blacklotus
                  last edited by

                  @luma:

                  I think it's possible to configure multiple subnet in the future pfSense 2.0 platform.

                  wow finally! that looks promising! now just have to wait for 2.0…
                  sigh...

                  1 Reply Last reply Reply Quote 0
                  • F
                    focalguy
                    last edited by

                    I think I asked the same thing here http://forum.pfsense.org/index.php/topic,14633.msg77791.html but I didn't describe it as well.

                    It will definitely be nice to do it in 2.0! I hope that's what I'm reading on that link.

                    1 Reply Last reply Reply Quote 0
                    • R
                      rwalker
                      last edited by

                      @jimp:

                      Multiple subnets w/IPSec are possible in 1.2.x in a non-obvious way, and there are some issues, but you can try it to see if it works for you:

                      http://doc.pfsense.org/index.php/IPSec_with_Multiple_Subnets

                      It didn't work for me, but I think that was mainly due to the fact that I was using a mobile tunnel and not a static site-to-site tunnel. The parts of my VPN that needed multiple subnets got moved to an OpenVPN tunnel and have been working happily ever since.

                      Parallel tunnels works.  You have to make sure ALL settings (except the network) are exactly the same, but it works.  I have this between pfSense <-> pfSense and pfSense <-> Cisco.

                      Roy

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.