Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ipsec tunnel beetwen Fortigate and pfsense

    Scheduled Pinned Locked Moved IPsec
    9 Posts 3 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Rostyslav DidusR
      Rostyslav Didus
      last edited by

      Hello guys.
      Got ipsec tunnel beetwen them.

      Can't find on pfsense side how to add route to LAN behind Fortigate fireweall.
      Fortigate allows adding route through the ipsec tunnel.So I did it.
      Pfsense doesn't got IPsec interfaces,so I can't add route through the tunnel.

      Therefore my ping requests from LAN behind Fortigate are reaching pfsense,but echo replies don't know how to back home.

      Is there a way to add route through Ipsec tunnel on pfsense?

      ShooterScreenshot-23-10-21-135.png

      1 Reply Last reply Reply Quote 0
      • Rostyslav DidusR
        Rostyslav Didus
        last edited by

        There are remote clients(10.10.30.0/24) who connect to Fortigate remotely(vpn).
        Exactly this network should be known by pfsence to work with.But,I can't add it as a route through pfsense ipsec channel on pfsense side.

        1 Reply Last reply Reply Quote 0
        • C
          cswroe
          last edited by

          Do you have the lan as a P2? This seems pretty straightforward unless I am missing something. I have a couple fortigates I connect to and similar situations as this.

          Rostyslav DidusR 1 Reply Last reply Reply Quote 0
          • Rostyslav DidusR
            Rostyslav Didus @cswroe
            last edited by

            @cswroe said in ipsec tunnel beetwen Fortigate and pfsense:

            Do you have the lan as a P2? This seems pretty straightforward unless I am missing something. I have a couple fortigates I connect to and similar situations as this.

            Hello.Didn't get about P2...
            Well,if I use NAT at Fortigate,its ok.Packets are NATed and traffic flows fine between 10.10.30.0/24 and 10.10.96.0/23
            But I want to get functionality without NAT.

            Can you check if possible..How to add route through ipsec at pfsense side.

            Diagram is here.ShooterScreenshot-24-10-21-139.png

            1 Reply Last reply Reply Quote 0
            • C
              cswroe
              last edited by cswroe

              You should have P2 entries under the P1 VPN entry to establish the far-end networks.
              Capture.JPG

              You will need one on the pfsense for 10.10.30.0/24 local subnet
              There will be a similar entry on the Fortigate side for the 10.10.96.0/23

              https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/configure.html#phase-2-settings

              B 1 Reply Last reply Reply Quote 1
              • Rostyslav DidusR
                Rostyslav Didus
                last edited by Rostyslav Didus

                It is done.
                Thanks for your help.

                ShooterScreenshot-24-10-21-145.png

                1 Reply Last reply Reply Quote 0
                • B
                  boi @cswroe
                  last edited by

                  @cswroe hi there

                  do I understood it correctly that pfsense doesn't need to have configured static routes to route traffic between opposite LANs as in regular network equipment (cisco fortinet etc.)?

                  C 1 Reply Last reply Reply Quote 0
                  • C
                    cswroe @boi
                    last edited by

                    @boi As long as pfsense knows what to do what the IP requested (P2 entry) and there are firewall rules permitting it, there should be no need for a static route.

                    B 1 Reply Last reply Reply Quote 2
                    • B
                      boi @cswroe
                      last edited by

                      @cswroe thanks for quick reply I appreciate it.

                      maybe you could give a hint regarding load balancing algorithm in case with specific remote LAN reachable behind two separate tunnels? will it be ECMP?

                      pfsense-p2.png

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.