Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Allow device from vlan A to connect over ipsec to device in vlan B

    IPsec
    2
    5
    495
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      DonZalmrol last edited by

      Hi,

      I'll try to explain myself as best as I can.

      We have a S2S in place between two sites (A and B), but we have a networking device that is location bound and can only be used from the first location (A).

      Now with covid I'm trying to set up a way to access this device remotely over our S2S to "trick" the device that a new vlan on site B is in the same network. So that our users can access it from the other site or even through openvpn.

      Future wise another device will be installed on location B and needs to communicate with the first device on location A.

      Is this possible to set this up?

      e.g. 192.168.1.1/24 on both site A and B with static routing.

      Thanks!

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @DonZalmrol last edited by

        @donzalmrol
        You can do a sort of NAT in IPSec using PAT-style on site A: NAT with IPsec Phase 2 Networks

        D 1 Reply Last reply Reply Quote 0
        • D
          DonZalmrol @viragomann last edited by

          @viragomann Thanks will look into this.
          Also forget to add, the device sends out its own DHCP. Can I forward this over the s2s?

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @DonZalmrol last edited by

            @donzalmrol
            DHCP? You mean you want to pull an IP from the other site?
            I can't see any sense for doing this at all, and it might end up in routing issues.

            D 1 Reply Last reply Reply Quote 0
            • D
              DonZalmrol @viragomann last edited by

              This looks indeed not possible to do.
              Post may be locked.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post