Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfsense site-to-site vti tunnel with 1:1 NAT for conflicting subnets

    Scheduled Pinned Locked Moved General pfSense Questions
    2 Posts 2 Posters 504 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • semiraueS
      semiraue
      last edited by semiraue

      Hi All,

      I have below setup across two sites. my client laptop is on site1.

      Untitled Diagram.jpg

      our site2 got conflicting subnet 192.168.10.0/24. I need to use 1:1 NAT to access it from site1

      something like, from site1 if I try to ping 192.168.11.0/24 it should be natted to 192.168.10.0/24.

      I tested this with creating 1:1 nat on site2 pfsense.
      interface - ipsec
      External subnet IP - 192.168.11.0/24
      Internal IP - 192.168.10.0/24

      and added static route 192.168.11.0/24 to site1 pfsense to send traffic to site2 pfsense via ipsec tunnel. now I can ping to remote site 192.168.10.0/24 network by pinging 192.168.11.0/24. but I cannot ssh or access any other services on remote end

      Also note that in site2 some servers not using pfsense as a gateway. so I had to use outbound nat to reach to those servers

      can anyone help with this ?

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        NATing on the VTI tunnels is one of the noted restrictions:
        https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/routed-vti.html#vpn-ipsec-vti-firewall

        You can only do that by applying it to the assigned interfaces and you can only do that by switching the IPSec filter mode which means you can no longer use policy based IPSec tunnels.

        You could just add an OpenVPN server at site2 and connect to it directly?

        Steve

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.