Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Routing between 3 Site to Site VPNs (IPSEC)

    Scheduled Pinned Locked Moved IPsec
    5 Posts 2 Posters 661 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pfeffis80
      last edited by

      Hi there,

      hopefully everybody is fine. We have the following infrastructure.

      Site A 192.168.1.x
      Site B 192.168.2.x
      Site C 192.168.3.x

      Headquarter (HQ) 192.168.10.x

      Site A, B and C are connected to HQ via IPSEC. So,
      Site A can see HQ and HQ can see Site A.
      Site B can see HQ and HQ can see Site B.
      Site C can see HQ and HQ can see Site C.

      Now we want to configure that

      Site A can see Site B and C and HQ
      Site B can see Sita A and C and HQ and
      Site C can see Site A and B and HQ

      Is it possible to configure that. If, which way is recommended?

      Thx
      M

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Yes, that is possible. You just need to add an appropriate set of Phase 2 entries to cover all of the possible paths. For example, on the tunnel between site A and HQ, you need P2 entries for A<->HQ, A<->B and A<->C, and firewall rules to allow what you want to flow in each direction.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • P
          pfeffis80
          last edited by

          Ok, done. P2 configured on HQ and Firewall Rules as well. Do we have to configure something more on the Sites A, B and C? The Sites A, B and C are LANCOM Router.

          Thanks

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            You need all of the equivalent P2s on each site. They all need to know to send traffic for the other sites to/through HQ.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • P
              pfeffis80
              last edited by

              Ok thx,

              anybody knows where to configure the P2 entries in a LANCOM Router?

              1 Reply Last reply Reply Quote 0
              • C couteauabeurre referenced this topic on
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.