Route network over IPSec



  • I have two pfsense routers set up at two homes. Site to Site IPSec is working great. I can ping and see everything between the two homes.

    At one home I have one subnet 192.168.50.0/24 and at home two I have two subnets 192.168.1.0/24 and 192.168.30.0/24.

    I want to route all Internet traffic only from the 192.168.30.0/24 net from home two to home one.

    I followed the tutorial on how to route all traffic between sites, but when I do that my dns stops working at home two (192.168.1.0/24).
    https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/routing-internet-traffic-through-a-site-to-site-ipsec-vpn.html

    I have the 192.168.30.0/24 net on a VLAN and the IPSec config:

    Home 2:
    Screen Shot 2020-07-30 at 11.06.54 AM.png

    NAT:
    Screen Shot 2020-07-30 at 11.08.21 AM.png

    Home 1 IPSec:
    Screen Shot 2020-07-30 at 11.10.07 AM.png

    Home 1 Outbound NAT:
    Screen Shot 2020-07-30 at 11.12.52 AM.png

    What am I missing?



  • Here is a diagram of the network topology

    Home 2 you can think of as remote site with two networks. One network is site to site, while the other network should route all traffic to the HQ (Home 1).

    Screen Shot 2020-07-30 at 1.25.03 PM.png


Log in to reply