Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    setup ipsec hub and spokes

    Scheduled Pinned Locked Moved IPsec
    4 Posts 2 Posters 586 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      snease
      last edited by

      So I need to setup a hub and 2 spokes and it currently looks like this

      hub ipsec
      p1 hub to site a
      -p2: site a lan to site a lan
      -p2: site b lan to site a lan
      p1 hub to site b
      -p2: hub lan to site b vlan
      -p2: site a lan to site b vlan

      site a ipsec
      p1 site a to hub
      -p2 site a lan to hub lan
      -p2 site a lan to site b vlan

      site b ipsec
      p1 site b to hub
      -p2 site b vlan to hub lan
      -p2 site b vlan to site a lan

      I can ping from site a to hub and site b to hub, but I can't seem to reach site b from site a. Many resources I've read says this is how ipsec hub and spoke is setup, and I also checked firewall rules to make sure everything is allowed to pass through. At this point I'm not sure what the problem is, could it be because site b is using vlan?

      Thanks in advance!

      J 1 Reply Last reply Reply Quote 0
      • J
        jgraham5481 @snease
        last edited by

        @snease
        Double check your configs, if all is pfsense, check your rules, I know this type of setup works even on non-routed ipsec mode. Maybe sniff out some traffic?

        1 Reply Last reply Reply Quote 0
        • S
          snease
          last edited by

          Thanks for the response @jgraham5481! After your comment I went on to check ipsec log and it turns out site b has an issue with dns and ipsec tunnel wasn't even established. At least now I can move on to solve the issue, thanks again!

          1 Reply Last reply Reply Quote 0
          • S
            snease
            last edited by

            piggy back off this thread, I have a mobile client ipsec tunnel set up on site a, and I've been trying to figure out a way for that mobile client (sub net 192.168.117.x) to reach site b in that hub and spokes structure. I tried adding a new p2 to the site a -> hub p1 with local subnet being 192.168.117.x remote subnet being the hub subnet. On the hub I added p2 with local being hub subnet and remote 192.168.117.x subnet. So far the mobile client can't connect to hub. I'm not too experienced with setting up tunnels using ipsec, does anyone have success in setting up similiar network?

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.