• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Can I run multiple IPSec Site-to-Site Tunnels

Scheduled Pinned Locked Moved IPsec
4 Posts 3 Posters 1.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • L
    latency0ms
    last edited by Jul 18, 2022, 8:15 AM

    Hello

    I have successfully set up an IPSec site-to-site tunnel with a customer, everything is working just fine.

    I was wondering if I could set up and run multiple IPSec tunnels with different customers at the same time. Do I have to define a new port per customer / connection like with OpenVPN? Or do I need to assign one separate WAN Address / Interface per IPSec Tunnel / Customer?

    • How are the individual IPSec tunnels distinguished from each other?
    • What happens if two customers have the same subnet?

    Your answers are very much appreciated.

    Thank you.

    1 Reply Last reply Reply Quote 0
    • T
      Thale
      last edited by Jul 22, 2022, 12:48 PM

      You can run multiple IPSEC tunnels to different locations at the same time, and can use the same interface for them. A rough answer about distinguishing between them is that separate Phase 1 tunnels are distinguished by the start and end points defining the tunnel.

      If two customers have the same subnet in use in their network, you will only be able to connect to one of them in your Phase 2 setup. Your system would have no way to know which one to route traffic to if you had a connection to both. If one of them uses multiple subnets in their network, and only one of them overlaps, then you could still connect to the other non-duplicate subnets.

      L 1 Reply Last reply Jul 22, 2022, 12:49 PM Reply Quote 1
      • L
        latency0ms @Thale
        last edited by Jul 22, 2022, 12:49 PM

        @thale That makes sense, thanks for the explenation!

        V 1 Reply Last reply Jul 22, 2022, 1:59 PM Reply Quote 0
        • V
          viragomann @latency0ms
          last edited by Jul 22, 2022, 1:59 PM

          @latency0ms
          Want to add, there is an option to get two overlapping remote subnets to work by NAT in phase 2. However, this has to be configured on one of the remote endpoints.

          1 Reply Last reply Reply Quote 0
          1 out of 4
          • First post
            1/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received