• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPSec local subnet behind router

Scheduled Pinned Locked Moved IPsec
7 Posts 2 Posters 605 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G
    gravinda
    last edited by Aug 14, 2023, 4:32 PM

    LAN subnet A ---->Router R ---->pfsense LAN subnet (B)------>pfsense WAN (B)<------IPSec Tunnel------>pfsense WAN (C)----->pfsense LAN subnet (C)

    I can access access pfsense LAN subnet C from pfsense LAN subnet B (which are directly connected to local IPs of LAN interfaces of pfsense boxes)

    But I cannot access pfsense LAN subnet C from LAN subnet A. (LAN subnet A is behind a router R).

    Please help to resolve.

    R 1 Reply Last reply Aug 14, 2023, 4:41 PM Reply Quote 0
    • R
      rcoleman-netgate Netgate @gravinda
      last edited by Aug 14, 2023, 4:41 PM

      How are you P2 configured?

      Screen shots are preferred here.

      Ryan
      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
      Requesting firmware for your Netgate device? https://go.netgate.com
      Switching: Mikrotik, Netgear, Extreme
      Wireless: Aruba, Ubiquiti

      G 1 Reply Last reply Aug 14, 2023, 4:59 PM Reply Quote 0
      • G
        gravinda @rcoleman-netgate
        last edited by Aug 14, 2023, 4:59 PM

        @rcoleman-netgate

        1bd05596-6e39-4444-8bb9-79b2b998a0fd-image.png

        I have setup a static route to 192.168.32.15 (in LAN subnet A) in pfsense box B

        192.168.253.0 is the remote subnet C

        R 1 Reply Last reply Aug 14, 2023, 5:05 PM Reply Quote 0
        • R
          rcoleman-netgate Netgate @gravinda
          last edited by Aug 14, 2023, 5:05 PM

          @gravinda Post the full P2 list ( the non-edit page but display) of all three... because they all play a role. You need to route A to B to C to get data to move properly.

          Ryan
          Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
          Requesting firmware for your Netgate device? https://go.netgate.com
          Switching: Mikrotik, Netgear, Extreme
          Wireless: Aruba, Ubiquiti

          G 1 Reply Last reply Aug 15, 2023, 2:32 PM Reply Quote 0
          • G
            gravinda @rcoleman-netgate
            last edited by Aug 15, 2023, 2:32 PM

            @rcoleman-netgate we setup our network as in the diagram.1.png

            In 10.248.32.15: Added route to 192.168.253.128 via R
            In R: added route to 192.168.253.128 via 10.32.192.209
            Can ping 10.32.192.209 from 10.248.32.15
            Can ping 192.168.253.128 from 10.32.192.88 (added route to 192.168.253.128 via 10.32.192.209) even without P2.

            But cannot ping 192.168.253.128 from 10.248.32.15
            We don’t have access to checkpoint firewall.

            R 1 Reply Last reply Aug 15, 2023, 2:45 PM Reply Quote 0
            • R
              rcoleman-netgate Netgate @gravinda
              last edited by Aug 15, 2023, 2:45 PM

              @gravinda OK.

              I was expecting something like this: 9adc6634-9576-4226-af6c-087f1abd8007-image.png

              Ryan
              Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
              Requesting firmware for your Netgate device? https://go.netgate.com
              Switching: Mikrotik, Netgear, Extreme
              Wireless: Aruba, Ubiquiti

              G 1 Reply Last reply Aug 15, 2023, 2:49 PM Reply Quote 0
              • G
                gravinda @rcoleman-netgate
                last edited by Aug 15, 2023, 2:49 PM

                @rcoleman-netgate 2.png

                1 Reply Last reply Reply Quote 0
                1 out of 7
                • First post
                  1/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received