<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Routing Traffic Across 2 VPNs]]></title><description><![CDATA[<p dir="auto">Been trying to wrap my brain around this and for some reason I can't figure it out.</p>
<p dir="auto">Long story short, I have a wireguard mobile VPN, the client on that VPN needs to access a service on a subnet that the WireGuard "server" has a connection to over IPSec.</p>
<p dir="auto">So: client &gt; WireGuard "server" pfsense &gt; IPsec VPN &gt; remote service</p>
<p dir="auto">I've got rules in place to pass the traffic on WireGuard to the subnets across the IPsec VPN, but no matter what I do pfSense running WireGuard replies with a syn closed instead of forwarding the packets.</p>
<p dir="auto">I'm sure it's something simple that I'm missing but just need another set of eyes on it I guess.</p>
]]></description><link>https://forum.netgate.com/topic/171220/routing-traffic-across-2-vpns</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 05:55:10 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/171220.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 31 Mar 2022 20:48:02 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Routing Traffic Across 2 VPNs on Thu, 31 Mar 2022 21:38:59 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/stephenw10">@<bdi>stephenw10</bdi></a> You are 100% absolutely right, knew it had to be something stupid I was missing lol. Good to go now ,thanks!</p>
]]></description><link>https://forum.netgate.com/post/1035549</link><guid isPermaLink="true">https://forum.netgate.com/post/1035549</guid><dc:creator><![CDATA[planedrop]]></dc:creator><pubDate>Thu, 31 Mar 2022 21:38:59 GMT</pubDate></item><item><title><![CDATA[Reply to Routing Traffic Across 2 VPNs on Thu, 31 Mar 2022 21:35:18 GMT]]></title><description><![CDATA[<p dir="auto">If you're using policy based IPSec (not VTI, route based) then you need a phase 2 policy in the IPSec tunnel to cover the traffic from the Wireguard subnet to the remote service subnet. It sounds like you don't have one so pfSense uses it;s default route to try to reach it.</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/1035548</link><guid isPermaLink="true">https://forum.netgate.com/post/1035548</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Thu, 31 Mar 2022 21:35:18 GMT</pubDate></item><item><title><![CDATA[Reply to Routing Traffic Across 2 VPNs on Thu, 31 Mar 2022 21:29:05 GMT]]></title><description><![CDATA[<p dir="auto">So now I've confused myself more, it seems that pfSense is sending these packets outside it's default gateway (wan) as if it doesn't have a route but it definitely has a route since every LAN interface directly on pfSense can send traffic over this IPSec VPN just fine.</p>
]]></description><link>https://forum.netgate.com/post/1035547</link><guid isPermaLink="true">https://forum.netgate.com/post/1035547</guid><dc:creator><![CDATA[planedrop]]></dc:creator><pubDate>Thu, 31 Mar 2022 21:29:05 GMT</pubDate></item></channel></rss>