Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Best solution Road warrior to IPSec SITE toSITE

    Scheduled Pinned Locked Moved IPsec
    2 Posts 1 Posters 362 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      Riccardo Prandini
      last edited by

      Hi,
      I have build succesfully with the help of @viragomann a Vpn site to site.

      VPN SITE to SITE with NAT

      So I have:

      IPSEC

      (our local-subnets)----(172.21.0.0/16)vlanX[FIREWALL]wan(192.168.0.2)----(192.168.0.1)ISP-Router(188.218.123.123)-----{internet}----(62.97.2.6)wan[Remote-GW-Peer]lan----(remote-subnets)
      

      I have 2 phase 2 to go to remote site be sufficient: 10.208.0.0/14, 10.100.9.0/24.
      there is also a NAT rule to go to those lan VPN SITE to SITE with NAT

      alt text

      I have also crated a vpn for road warrior users. using the OpenVPN server. It works

      OpenVPN-Guide

      In this case the OpenVpn LAN is 172.31.0.0./16

      I can connect happy with the LAN 172.21.0.0./16 because as the guide suggested i have added this lan inside the LocalNetwork.

      alt text

      ========================================================

      I have now to made possible for the road warrior to navigate inside the ipsec tunnel.
      if he hasto go to the 10.208.0.0/14 he is natted and redirected inside the tunnel

      Reading somewhere i have found that this could be the solution (adding more phase2)
      https://forum.netgate.com/topic/105946/openvpn-site-to-site-roadwarrior/3

      Is this the way??

      1 Reply Last reply Reply Quote 0
      • R
        Riccardo Prandini
        last edited by Riccardo Prandini

        The 1 step was to push this config to clients, so the packet on VPN ipse is routed inside the Open VPN tunnel

        alt text

        Under local networks there are :

        Lan,
        the remote net identified in phase2 n.1
        the remote net identified in phase2 n.2

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.