<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Route traffic of local IP through OpenVPN site-to-site client?]]></title><description><![CDATA[<p dir="auto">I have 2 pfsense with site-to-site OpenVPN set up. Site A is primary, and Site B is remote. Site B is sitting behind NAT, so it had to be the client to connect to Site A's OpenVPN server and forming the site-to-site. I want to route the traffic of certain client IPs at Site A through to Site B. How do I configure NAT/routing at Site A to accomplish this?</p>
]]></description><link>https://forum.netgate.com/topic/148156/route-traffic-of-local-ip-through-openvpn-site-to-site-client</link><generator>RSS for Node</generator><lastBuildDate>Sun, 19 Jul 2026 18:44:19 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/148156.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 15 Nov 2019 20:41:27 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Route traffic of local IP through OpenVPN site-to-site client? on Sat, 16 Nov 2019 10:15:18 GMT]]></title><description><![CDATA[<p dir="auto">Yea that fixed it. I didn't have to add a gateway on the pfsense at site B. I added the interface/gateway on site A side and created rules in LAN tab to route IPs in alias over to site-to-site interface gateway. Then pushed the routes to site B in the site-to-site OpenVPN server configuration on site A. On site B, I only needed to create NAT outbound rules so that packets would be able to get out to the internet.</p>
]]></description><link>https://forum.netgate.com/post/876029</link><guid isPermaLink="true">https://forum.netgate.com/post/876029</guid><dc:creator><![CDATA[eroji]]></dc:creator><pubDate>Sat, 16 Nov 2019 10:15:18 GMT</pubDate></item><item><title><![CDATA[Reply to Route traffic of local IP through OpenVPN site-to-site client? on Sat, 16 Nov 2019 10:06:33 GMT]]></title><description><![CDATA[<p dir="auto">Tried to restart the box at site B?</p>
<p dir="auto">Basically adding an interface to the VPN instance should do nothing than induce pfSense to add the reply-to flag to packets coming in that interface.<br />
However, if you only direct internal traffic from A to B and have set that source in the "Remote Network" at B, the interface is not necessary.</p>
]]></description><link>https://forum.netgate.com/post/876028</link><guid isPermaLink="true">https://forum.netgate.com/post/876028</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Sat, 16 Nov 2019 10:06:33 GMT</pubDate></item><item><title><![CDATA[Reply to Route traffic of local IP through OpenVPN site-to-site client? on Fri, 15 Nov 2019 23:05:43 GMT]]></title><description><![CDATA[<p dir="auto">Well I went added, then deleted the interface on site B for the site-to-site OpenVPN, now I lost the ability to connect to it completely. I can still see it connect to the pfsense at Site A, but I cannot route to Site B's pfsense IP...</p>
]]></description><link>https://forum.netgate.com/post/876003</link><guid isPermaLink="true">https://forum.netgate.com/post/876003</guid><dc:creator><![CDATA[eroji]]></dc:creator><pubDate>Fri, 15 Nov 2019 23:05:43 GMT</pubDate></item><item><title><![CDATA[Reply to Route traffic of local IP through OpenVPN site-to-site client? on Fri, 15 Nov 2019 22:14:58 GMT]]></title><description><![CDATA[<p dir="auto">Yes, interfaces should be assigned on both site.<br />
There no interface configuration needed, only assign it to the OpenVPN instance, enable it and set a friendly name if you want.<br />
The IP configuration is done by OpenVPN.</p>
]]></description><link>https://forum.netgate.com/post/876002</link><guid isPermaLink="true">https://forum.netgate.com/post/876002</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Fri, 15 Nov 2019 22:14:58 GMT</pubDate></item><item><title><![CDATA[Reply to Route traffic of local IP through OpenVPN site-to-site client? on Fri, 15 Nov 2019 22:08:54 GMT]]></title><description><![CDATA[<p dir="auto">For the interface, do I need to add it on both sides? What IP do I give the gateway after adding the interface, or is it arbitrary?</p>
]]></description><link>https://forum.netgate.com/post/876001</link><guid isPermaLink="true">https://forum.netgate.com/post/876001</guid><dc:creator><![CDATA[eroji]]></dc:creator><pubDate>Fri, 15 Nov 2019 22:08:54 GMT</pubDate></item><item><title><![CDATA[Reply to Route traffic of local IP through OpenVPN site-to-site client? on Fri, 15 Nov 2019 22:05:43 GMT]]></title><description><![CDATA[<p dir="auto">Assign an interface to the OpenVPN instances and activate it on both sites if you haven't already done.<br />
This effects that pfSense creates a gateway for the VPN using the remote host IP.</p>
<p dir="auto">That gateway can then be used for <a href="https://docs.netgate.com/pfsense/en/latest/routing/directing-traffic-with-policy-routing.html" target="_blank" rel="noopener noreferrer nofollow ugc">policy routing</a>.<br />
To do so, add all IPs you want to route over the VPN to an alias. Then add a firewall pass rule to the  interface the traffic is coming in, at source use the alias, at destination set the destination IP you want or any if you want to direct the whole traffic from the source devices to the other site.<br />
Expand the advanced options, go to gateway and select the appropriate OpenVPN gateway.</p>
<p dir="auto">If the destination is in the internet you need additionally an outbound NAT rule for these source network at site B.</p>
]]></description><link>https://forum.netgate.com/post/876000</link><guid isPermaLink="true">https://forum.netgate.com/post/876000</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Fri, 15 Nov 2019 22:05:43 GMT</pubDate></item></channel></rss>