Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Placing old Firewall/VPN behind new PFSense box

    Scheduled Pinned Locked Moved NAT
    1 Posts 1 Posters 199 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      donb
      last edited by

      I'm getting started on replacing gateway devices at several locations, 1 main site and 6 external sites. Each external site currently has a site-to-site OpenVPN using Smoothwall Express. The main also runs openVPN for single remotes with openVPN on users' laptops.

      At the main site, I'm looking at the best way to keep the status quo functioning while I work with each branch site and remote worker to update them to new VPN tunnels. The OpenVPN server/client on the current device is limited enough that any change to try and make it connect via openVPN to a netgate device risks breaking everything, which can't happen. A few sites have frustratingly locked down modem/gateway devices which would force an IPSec tunnel through a double NAT, making it really slow and unstable in my experience.

      At the main, the netgate device will be at the edge of the network, with the old firewall/vpn behind it. From there, There's a few options:

      Port forward the existing VPN ports back to the old device. Routing could be a bit tricky to make sure incoming VPN connections have a route to the main site lan. The new VPNs would then have to use alternate ports, at least until the old tunnels are all decomissioned.

      The other possibility is a 1:1 nat setup, and use a completely different IP for the new tunnels on the new devices. Luckily I have multiple public IPs to work with.

      Does anyone have some experience with such a scenario, who can suggest the best approach?

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.