Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Access internet through IPSEC site to site VPN

    Scheduled Pinned Locked Moved NAT
    9 Posts 2 Posters 740 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mhzr
      last edited by

      Hello
      I have 2 Pfsense VMs in different datacenters in 2 different countries watch are covered by 2 different internet providers. The IPsec tunnel is stablished between them but my clients is Site A can not access the internet through Pfsense site B. both Pfsense VMs have access to the internet.
      I found Site A clients ip address in Site B pfsense filter log witch shows it passes their traffic, but clients in site A can not ping internet ip addresses, they just can ping pfsense Site B ip address.
      How I can solve this problem?!PFsense NAT.JPG

      1 Reply Last reply Reply Quote 0
      • M
        mhzr
        last edited by

        there is no any idea?!

        G 1 Reply Last reply Reply Quote 0
        • G
          gabacho4 Rebel Alliance @mhzr
          last edited by

          @mhzr I'd give the following a read and then make sure your setup is the same.

          https://docs.netgate.com/pfsense/en/latest/recipes/ipsec-s2s-route-internet-traffic.html

          M 1 Reply Last reply Reply Quote 0
          • M
            mhzr @gabacho4
            last edited by

            @gabacho4 said in Access internet through IPSEC site to site VPN:

            https://docs.netgate.com/pfsense/en/latest/recipes/ipsec-s2s-route-internet-traffic.html

            This is as same as your recommendation, for your information all screenshots are uploaded:

            Site A:

            PF-A.JPG PF-A2.JPG PF-A-ipsecrule.JPG PF-A-LANrule.JPG PF-A-NAT.JPG PF-A-wanrule.JPG

            Site B:

            pfb1.JPG pfb2.JPG pfbipsec.JPG pfbnat.JPG ![0_1622374731023_pfbwan.JPG](Uploading 100%)

            Thanks

            G 1 Reply Last reply Reply Quote 0
            • G
              gabacho4 Rebel Alliance @mhzr
              last edited by

              @mhzr your site B P2 appears to be wrong as the local network should be 0.0.0.0/0 whereas you have it set to WAN.

              M 1 Reply Last reply Reply Quote 1
              • M
                mhzr @gabacho4
                last edited by

                @gabacho4
                That's the greatest recommendation. The problem solved successfully.
                Many Thanks for your time.

                G 1 Reply Last reply Reply Quote 0
                • G
                  gabacho4 Rebel Alliance @mhzr
                  last edited by

                  @mhzr no problem at all. You were 99% of the way there. Enjoy!

                  1 Reply Last reply Reply Quote 0
                  • M
                    mhzr
                    last edited by

                    Again I faced such problem with OVPN Clients of Site A. OVPN Network in Site A has the same config in IPSEC configuration on both Sites and NAT configuration in Site B.
                    Thanks

                    1 Reply Last reply Reply Quote 0
                    • M
                      mhzr
                      last edited by

                      Solved

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.