<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[PFSENSE + IPSEC + NAT]]></title><description><![CDATA[<p dir="auto">We have a network with different subnets:</p>
<p dir="auto">10.0.0.0/23 Main<br />
10.0.2.0/25 Subnet<br />
10.0.3.0/24 Subnet<br />
10.0.4.0/27 Subnet<br />
10.0.5.0/26 Subnet<br />
10.0.X.0/24 Subnet</p>
<p dir="auto">We also have an IPSEC connection to provide mutual services (WEB and DNS) of which I have no control at the other end. The services of both have the 172.19.0.0/24 network as their origin and destination.<br />
In the PFSENSE (in high availability) I have a VIRTUAL IP 172.19.0.1 which is the gateway for the IPSEC tunnel.<br />
Currently I have the IPSEC tunnel working correctly but I have a router with addresses 172.19.0.5 and 10.0.0.5 doing NAT from networks 10.0.0.0 to network 172.19.0.0/24 to be able to send the traffic through the IPSEC tunnel (access to networks 172.19.10.0/24. 172.19.11.0/24, ...)</p>
<p dir="auto">I have done numerous tests to try to NAT the traffic from networks 10.0.X.0 to 172.19.0.1 and thus send through the IPSEC tunnel but I can't. The tests carried out are:</p>
<ul>
<li>Configure Outbound NAT to the IPSec interface</li>
<li>Configure Outbound NAT to the network interface 172.19.0.1 (CARP IP)</li>
<li>Configure Outbound NAT to the network interface 172.19.0.2 (IP PFSense)</li>
<li>Create another Virtual IP and use it for Outbound NAT.</li>
</ul>
<p dir="auto">Thanks for the help.</p>
]]></description><link>https://forum.netgate.com/topic/180324/pfsense-ipsec-nat</link><generator>RSS for Node</generator><lastBuildDate>Sat, 18 Jul 2026 14:41:05 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/180324.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 24 May 2023 12:45:35 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to PFSENSE + IPSEC + NAT on Fri, 26 May 2023 06:44:08 GMT]]></title><description><![CDATA[<p dir="auto">I have also posted this problem in the <a href="https://forum.netgate.com/topic/180360/pfsense-ipsec-nat">NAT section</a> with more information to see if someone can help me.</p>
<p dir="auto">Thanks you</p>
]]></description><link>https://forum.netgate.com/post/1106998</link><guid isPermaLink="true">https://forum.netgate.com/post/1106998</guid><dc:creator><![CDATA[Abelardo A.M.]]></dc:creator><pubDate>Fri, 26 May 2023 06:44:08 GMT</pubDate></item></channel></rss>