Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Openvpn Layer3 bridge

    Scheduled Pinned Locked Moved OpenVPN
    3 Posts 3 Posters 487 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sconvolt666
      last edited by

      i am testing a particular solution and i don't know how to fix it.
      I have 2 offices, which I will call headquarters A and headquarters B.
      Site A is connected in MPLS VPN with an external provider, I entered the pfsense network which is in the network with the wan interface, on this pfsense set the OpenVpn layer 3 server.
      Site B is connected via OpenVpn layer 3.
      The networks can be seen and function correctly, my problem is that the two offices must have two different IP classes but I should see the IPs of office B from office A in full.
      in practice, when I invoke a service from site A from site B, the IP that invokes the services is that of Pfsense.
      I tried to configure a layer2 tunnel but it doesn't allow me to manage two different network seeds. How can I handle the situation?

      JKnottJ johnpozJ 2 Replies Last reply Reply Quote 0
      • JKnottJ
        JKnott @sconvolt666
        last edited by

        @sconvolt666

        There's no such thing as a layer 3 bridge. Bridges are a layer 2 function. With OpenVPN, the normal method is TUN mode, which you route IP through. If you want a bridge, you have to use TAP mode.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @sconvolt666
          last edited by johnpoz

          @sconvolt666 said in Openvpn Layer3 bridge:

          when I invoke a service from site A from site B, the IP that invokes the services is that of Pfsense.

          Huh? then you didn't setup a site to site vpn... But you have setup a road warrior?

          With a site to site vpn, you would see the IP of the client.. There would be no natting going on.

          192.168.1/24 - pfsA -- vpn -- pfsB - 192.168.2/24

          When 192.168.1.x talks to 192.168.2.y, Y would see 192.168.1.x talking to it. And vise versa..

          https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-s2s-psk.html
          https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-s2s-tls.html

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.