<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OVPN Client ---&gt; PfSense ---&gt; IPSEC ---&gt; Server]]></title><description><![CDATA[<p dir="auto">I need to access an application on the other end of an IPSEC VPN through an OpenVPN client.</p>
<p dir="auto">I don't have access on the other end of IPSEC, so I can't create a phase 2 to declare my OpenVPN network and I can't use VTI.</p>
<p dir="auto">Attached is the network topology. I believe I will have to use a NAT, but I'm not getting it. Thanks to anyone who can help.<img src="/assets/uploads/files/1649561345127-topologia.jpeg" alt="topologia.jpeg" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/171443/ovpn-client-pfsense-ipsec-server</link><generator>RSS for Node</generator><lastBuildDate>Sat, 16 May 2026 06:05:20 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/171443.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 10 Apr 2022 03:29:11 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to OVPN Client ---&gt; PfSense ---&gt; IPSEC ---&gt; Server on Mon, 11 Apr 2022 14:31:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/vfisher">@<bdi>vfisher</bdi></a><br />
You need also to push the route to the remote IP to the OpenVPN clients, of course.<br />
So you have to add "172.31.17.150/32" to the "IPv4 Local Networks" in the server settings. Have you done this already?</p>
<p dir="auto">Also ensure that firewall rules on the VPN interface allow access.</p>
]]></description><link>https://forum.netgate.com/post/1037288</link><guid isPermaLink="true">https://forum.netgate.com/post/1037288</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Mon, 11 Apr 2022 14:31:23 GMT</pubDate></item><item><title><![CDATA[Reply to OVPN Client ---&gt; PfSense ---&gt; IPSEC ---&gt; Server on Mon, 11 Apr 2022 13:56:51 GMT]]></title><description><![CDATA[<p dir="auto">You are right...I don't have access to the other end, and the IT staff told me they can't set up a second phase 2.</p>
<p dir="auto">In the case of the OpenVPN that I use to connect to the office network is a Client to Site, I tried to include a route in the client, but it didn't work either.</p>
]]></description><link>https://forum.netgate.com/post/1037269</link><guid isPermaLink="true">https://forum.netgate.com/post/1037269</guid><dc:creator><![CDATA[Vfisher]]></dc:creator><pubDate>Mon, 11 Apr 2022 13:56:51 GMT</pubDate></item><item><title><![CDATA[Reply to OVPN Client ---&gt; PfSense ---&gt; IPSEC ---&gt; Server on Mon, 11 Apr 2022 07:58:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/vfisher">@<bdi>vfisher</bdi></a><br />
So you use already BINAT with quite small networks.</p>
<p dir="auto">The options to configure an additonal BINAT depends on the phase 2 of the remote site and I suspect that you don't know it.<br />
But since your existing P 2 translates already from a /24 to a /30 it's not an 1:1 translation anyway, but many to few.</p>
<p dir="auto">So I think you can do the same for the VPN clients. Add an additional P 2, at Local Network state the OVPN tunnel network and do all over settings equal to the existing P 2.</p>
]]></description><link>https://forum.netgate.com/post/1037204</link><guid isPermaLink="true">https://forum.netgate.com/post/1037204</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Mon, 11 Apr 2022 07:58:52 GMT</pubDate></item><item><title><![CDATA[Reply to OVPN Client ---&gt; PfSense ---&gt; IPSEC ---&gt; Server on Mon, 11 Apr 2022 03:06:43 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> Thanks for your answer!</p>
<p dir="auto">I don't know how to create an additional BINAT/PAT, I would be grateful if you could give me an example.</p>
<p dir="auto">Here is my phase 2 configuration screen.</p>
<p dir="auto">Thank you!<img src="/assets/uploads/files/1649646400241-phase2.png" alt="phase2.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/1037183</link><guid isPermaLink="true">https://forum.netgate.com/post/1037183</guid><dc:creator><![CDATA[Vfisher]]></dc:creator><pubDate>Mon, 11 Apr 2022 03:06:43 GMT</pubDate></item><item><title><![CDATA[Reply to OVPN Client ---&gt; PfSense ---&gt; IPSEC ---&gt; Server on Sun, 10 Apr 2022 08:58:48 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/vfisher">@<bdi>vfisher</bdi></a><br />
You can add an additional BINAT / PAT phase 2 using the same local network.<br />
How is your primary P 2 configured?</p>
<p dir="auto">At site B there is alrealy a BINAT rule?</p>
]]></description><link>https://forum.netgate.com/post/1037074</link><guid isPermaLink="true">https://forum.netgate.com/post/1037074</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Sun, 10 Apr 2022 08:58:48 GMT</pubDate></item></channel></rss>