• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Make Subnet reachable over IPsec using an IP in the very same Subnet

Scheduled Pinned Locked Moved IPsec
4 Posts 3 Posters 1.1k Views 2 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K Offline
    Kastenfrosch-48
    last edited by Kastenfrosch-48 Jan 11, 2023, 10:18 AM Jan 11, 2023, 10:02 AM

    Hello,

    I have to make some hosts in a LAN on a remote location reachable over an IPsec-Tunnel.
    At this point in time, theres only one Subnet available for me to initiate the VPN-connetion. Unfortunately, this is the very same network those hosts are also residing in.
    I want to initiate the IPsec-Tunnel from an IP inside this subnet. So the WAN-Interface and LAN interface would be connected to the same physical Network.

    Is there really no way to get this working with pfsense.

    From a routing perspective it makes total sense it wouldnt work, but maybe theres a way?

    Thanks in advance.

    N 1 Reply Last reply Jan 11, 2023, 10:31 AM Reply Quote 0
    • N Offline
      NogBadTheBad @Kastenfrosch-48
      last edited by Jan 11, 2023, 10:31 AM

      @kastenfrosch-48 you'd need to nat:-

      https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/phase-2-nat.html

      Much better to re IP one of the subnets IMO.

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      K 1 Reply Last reply Jan 11, 2023, 11:45 AM Reply Quote 0
      • K Offline
        Kastenfrosch-48 @NogBadTheBad
        last edited by Kastenfrosch-48 Jan 11, 2023, 11:45 AM Jan 11, 2023, 11:45 AM

        thanks, but i think you missunderstood me.

        The Issue is, that on one site i have only one network available to establish the VPN over the WAN interface, in wich the hosts i want to communicate with via the IPsec-tunnel also are.

        It would be a double-NAT situation on the WAN side of the pfsense-router, because i want to be indipendent from the sites own firewall.

        V 1 Reply Last reply Jan 11, 2023, 7:00 PM Reply Quote 0
        • V Offline
          viragomann @Kastenfrosch-48
          last edited by Jan 11, 2023, 7:00 PM

          @kastenfrosch-48
          Still not really clear, what you intend to achieve.

          Unfortunately, this is the very same network those hosts are also residing in.
          I want to initiate the IPsec-Tunnel from an IP inside this subnet.

          You want to initiate an IP from one of these remote machines to your pfSense and access the ohter remote network devices through it?

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received