Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Routing OpenVPN to IPsec site to site

    Scheduled Pinned Locked Moved Routing and Multi WAN
    4 Posts 2 Posters 354 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Steelhand
      last edited by Steelhand

      Hi all!

      Not sure where to post my question.
      I’m doing some tests using Pfsense as a gw for mgmt network for several sites.
      What I’m trying to do is use openvpn to connect to a pfsense which is running IPSec site-to-site to different locations providing access to mgmt network (firewall/switches/ap’s).

      I’m looking for a best practice setup for this or maybe some tips regarding routing.
      Since it will be serveral hundred subnets that will have to be accessible. How do i route this?
      Push route to openvpn clients?

      What’s the best way of doing this?

      1 Reply Last reply Reply Quote 0
      • dotdashD
        dotdash
        last edited by

        Just put the networks in IPv4 Local networks. You can summarize like 10.0.0.0/8.
        Alternatively, check the box for 'redirect gateway' and send everything through the vpn.
        Also make sure the remote p2's include the subnet you are using for openvpn.

        1 Reply Last reply Reply Quote 0
        • S
          Steelhand
          last edited by

          That’s also a thing..
          I do not want to run all the users traffic through this box.. this is for support.
          They should be able Be connected to openvpn connection all day ling to reach the different networks without tunneling all traffic that way.

          1 Reply Last reply Reply Quote 0
          • S
            Steelhand
            last edited by Steelhand

            And due to different reasons.. let say that site-to-to is 10.35.0.0/16.
            And openvpn clients need to be 192.168.xxx.xxx
            Due to restrictions of already used networks..
            And since it is IPSec site to site, they are not local networks, but routes into a local network.
            From 172.16.20.0/24 to 10.35.0.0/24 local.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.