NAT 1:1 ipsec tunnel and static routing.



  • Hello all.

    I have 2 pfsense boxes both have a SDSL WAN connection.

    On pfsense box 1 (192.168.1.253) i have 2 ipsec tunnels to network 192.168.2.0/24 and 192.168.3.0/24
    On pfsense box 2 (192.168.1.254) i have 2 ipsec tunnels to network 192.168.4.0/24 and 192.168.5.0/24

    On the pfsense box 1  i have 2 static routes to 192.168.4.0/24 and 192.168.5.0/24
    On the pfsense box 2  i have 2 static routes to 192.168.2.0/24 and 192.168.3.0/24

    This works well all clients in network 192.168.1.0/24 can connect to all networks.
    Some clients have gateway 192.168.1.253 and some have 192.168.1.254.

    Now i added a 1:1 NAT to my mailserver on PFSense box 1
    This way i can use a second WAN ip addres for my mailserver.
    All is working well, but now networks 192.168.4.0/24 and 192.168.5.0/24 can not reach the mailserver anymore.
    I need to set a route on the mailserver to 192.168.0.254 to networks 192.168.4.0/24 and 192.168.5.0/24

    How can this be i have a static route on pfsense box 1 that says the networks 192.168.4.0/24 and 192.168.5.0/24 are behind 192.168.0.254.

    Or am i missing something.
    regards,
    Johan


Log in to reply