NAT 1:1 ipsec tunnel and static routing.
Sylhouette last edited by
I have 2 pfsense boxes both have a SDSL WAN connection.
On pfsense box 1 (192.168.1.253) i have 2 ipsec tunnels to network 192.168.2.0/24 and 192.168.3.0/24
On pfsense box 2 (192.168.1.254) i have 2 ipsec tunnels to network 192.168.4.0/24 and 192.168.5.0/24
On the pfsense box 1 i have 2 static routes to 192.168.4.0/24 and 192.168.5.0/24
On the pfsense box 2 i have 2 static routes to 192.168.2.0/24 and 192.168.3.0/24
This works well all clients in network 192.168.1.0/24 can connect to all networks.
Some clients have gateway 192.168.1.253 and some have 192.168.1.254.
Now i added a 1:1 NAT to my mailserver on PFSense box 1
This way i can use a second WAN ip addres for my mailserver.
All is working well, but now networks 192.168.4.0/24 and 192.168.5.0/24 can not reach the mailserver anymore.
I need to set a route on the mailserver to 192.168.0.254 to networks 192.168.4.0/24 and 192.168.5.0/24
How can this be i have a static route on pfsense box 1 that says the networks 192.168.4.0/24 and 192.168.5.0/24 are behind 192.168.0.254.
Or am i missing something.