<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Question on IPsec Phase 2 NAT]]></title><description><![CDATA[<p dir="auto">I read this: https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/nat-with-ipsec-phase-2-networks.html</p>
<p dir="auto">Did I understand it correctly?</p>
<p dir="auto">If I want someone else to have an IPsec tunnel into my pfSense I can give them whatever subnet address they want, for instance 10.10.10.0/24, if I use binary 1:1 NAT?</p>
<p dir="auto">Does that also mean that I can have several IPsec tunnels using the same subnet address, for instance 10.10.10.0/24 that I will NAT into other real IP addresses?</p>
<p dir="auto">Example:<br />
Link 1:  IPsec tunnel connects to 10.10.10.0/24 but real IPs are 192.168.1.0/24.<br />
Link 2:  IPsec tunnel connects to 10.10.10.0/24 but real IPs are 192.168.2.0/24.</p>
<p dir="auto">Thanks in advance!</p>
]]></description><link>https://forum.netgate.com/topic/153267/question-on-ipsec-phase-2-nat</link><generator>RSS for Node</generator><lastBuildDate>Sat, 14 Mar 2026 02:44:29 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/153267.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 05 May 2020 13:17:41 GMT</pubDate><ttl>60</ttl></channel></rss>