Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT whole network to IPsec

    Scheduled Pinned Locked Moved IPsec
    mikrotikipsecnatsqlrdp
    1 Posts 1 Posters 740 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      teh42eem00
      last edited by

      Hello Everyone, I'm currently working on a project to migrate existing Mikrotik based network to pfSense. It worked almost perfectly except IPsec tunnels.

      I managed to connect all PH1 and PH2 but I can see it's working in a different way in pfSense.

      So I have IPsec IKEv1 tunnel with following settings:
      our remote/virtual network inside tunnel:
      192.168.50.0/30
      customers remote network:
      195.182.52.136/32

      I would like to provide access to customer's network from all my LAN clients, for example 10.131.0.0/16

      That's how PH2 worked in Mikrotik:

      0bec04a5-5e21-41ad-ac0b-22bc4d21299e-image.png

      and then simple src-nat worked to NAT anyone trying to connect to this tunnel
      b77bccb3-5c80-412c-ac5a-585cb591f06a-image.png

      Is there any other way than multiple PH2 to get similar functionality?

      That's how I have it currently configured with PH2 in pfSense but the problem is if I add more than 4 PH2 entries only 4 of them are working and if I force connect them from status > ipsec it disconnects some other ones.
      1cd76443-35e0-4674-984d-4adcd62fe28c-image.png

      I know I could choose overload NAT to NAT whole network to single IP but it would require change in tunnel configuration and it's not a simple thing with our customers.

      Another issue I have is related to services inside this tunnel, after switch to pfsense I have following errors in SQL and RDP, it worked perfectly on Mikrotik:

      213eb1fe-1711-46a5-9713-64f9c52203fd-image.png
      6c2e92f5-3ad2-47a4-9d9b-c47d63299e15-image.png

      I hope someone in this community had similar issues, let me know if you need any additional information. Thanks!

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.