Port forward + Source NAT + IPSec VTI
-
-
It's probably routing through the VIP interface instead of through the VTI
On which interface are you seeing those packets? On the VTI or on the one where you have your VIPs (Guessing its WAN)?
-
@dmendez-netgate hello! Captured from VTI. Actually I did this task by using tunnel mode instead VTI. But it's still interesting why it doesn't work through VTI...
-
@DirectRaw If that packet capture was on the VTI, it means your routes on pfSense1 are correct.
What about pfSense2? Do you have a route to send traffic to destination 172.19.0.1 through the VTI?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.