<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Use remote site&#x27;s ip address to reach for specific host]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I've ipsec tunnel installed as below(IP adresses imaginary due to security reasons);</p>
<p dir="auto">SITE A :<br />
LOCATION : Paris<br />
WAN : 172.177.77.77<br />
LAN : 192.168.10.254</p>
<p dir="auto">SITE B:<br />
LOCATION : Istanbul<br />
WAN : 174.174.74.74<br />
LAN : 192.168.20.254</p>
<p dir="auto">SITE B's internet traffic goes through SITE A because VOIP system only allows traffic from 172.177.77.77 so that's why phase 2 settings;<br />
SITE A : LAN 0.0.0.0/0<br />
SITE B : RLAN 0.0.0.0/0</p>
<p dir="auto">With this config when you go whatismyip.com from Istanbul it shows your ip as 172.177.77.77 and voip systems works because it thinks that you are in Paris not in Istanbul :)</p>
<p dir="auto">But it also messes with Istanbul users google searches or all other HTTP &amp; HTTPS traffics because all other platforms thinks that you are in Paris too, i was wondering is it possible to make an firewall or NAT rule to force pfsense if any traffic goes to 192.168.10.254 (VOIP router's ip in france) through tunnel use Paris's WAN ip and for all other traffics use Istanbul's WAN ip.</p>
<p dir="auto">Unfortunately we can not allow Istanbul's ip to reach to VOIP central, the company directly says no, i'm trying to find a work arround.</p>
<p dir="auto">Cheers.</p>
]]></description><link>https://forum.netgate.com/topic/181065/use-remote-site-s-ip-address-to-reach-for-specific-host</link><generator>RSS for Node</generator><lastBuildDate>Tue, 12 May 2026 01:04:13 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/181065.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 27 Jun 2023 09:50:55 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Use remote site&#x27;s ip address to reach for specific host on Tue, 27 Jun 2023 16:04:34 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/yeahmagnets">@<bdi>yeahmagnets</bdi></a><br />
You have to policy route the VoIP traffic to the remote VPN endpoint. But this is not possible with policy based IPSec. I think, it can be done with routed IPSec (VTI), but I never set this up by myself.</p>
<p dir="auto">You can policy route the traffic with OpenVPN or Wireguard though.</p>
]]></description><link>https://forum.netgate.com/post/1112513</link><guid isPermaLink="true">https://forum.netgate.com/post/1112513</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Tue, 27 Jun 2023 16:04:34 GMT</pubDate></item></channel></rss>