<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[redirect to PFsense IPsec tunnel endpoit which has public IP]]></title><description><![CDATA[<p dir="auto">I have got a working IPsec connection where the Remote subnet has a non internet IP address (105.x.y.z/25).</p>
<p dir="auto">Trying to access this address of course leads to the public internet.</p>
<p dir="auto">How can I redirect all request to 10X.x.y.z/25 to the IPSec tunnel (and within that to the Local Subnet of the connected side)? (Of course the "real" 10X.x.y.z/25 addresses will not be reachable anymore.)</p>
]]></description><link>https://forum.netgate.com/topic/185545/redirect-to-pfsense-ipsec-tunnel-endpoit-which-has-public-ip</link><generator>RSS for Node</generator><lastBuildDate>Mon, 15 Jun 2026 05:08:36 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/185545.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 15 Jan 2024 07:17:06 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to redirect to PFsense IPsec tunnel endpoit which has public IP on Mon, 15 Jan 2024 11:58:26 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a><br />
It is policy-based tunnel (Tunnel IPv4).</p>
<p dir="auto">Phase2 is working (status connected).</p>
<p dir="auto">Status-&gt;SystemLogs-&gt;IPSEc has no corresponding entries.</p>
<p dir="auto">But you said " and the subnet is not routed through the tunnel": This is exactly the problem - how to do this? As there are no thus options in the IPSec tunnel settings ("NAT/BINAT translation" should not be the corresponding option.)</p>
]]></description><link>https://forum.netgate.com/post/1147918</link><guid isPermaLink="true">https://forum.netgate.com/post/1147918</guid><dc:creator><![CDATA[admin_axx]]></dc:creator><pubDate>Mon, 15 Jan 2024 11:58:26 GMT</pubDate></item><item><title><![CDATA[Reply to redirect to PFsense IPsec tunnel endpoit which has public IP on Mon, 15 Jan 2024 11:48:56 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/admin_axx">@<bdi>admin_axx</bdi></a><br />
Is it a policy-based tunnel or a VTI?</p>
<p dir="auto">If it is a policy-based and the subnet is not routed through the tunnel, the phase 2 doesn't work. Maybe something wrong in the settings.<br />
You can verify the log.</p>
]]></description><link>https://forum.netgate.com/post/1147917</link><guid isPermaLink="true">https://forum.netgate.com/post/1147917</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Mon, 15 Jan 2024 11:48:56 GMT</pubDate></item><item><title><![CDATA[Reply to redirect to PFsense IPsec tunnel endpoit which has public IP on Mon, 15 Jan 2024 11:40:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a></p>
<p dir="auto">The tunnel itself i(phase 1 and phase 2) is working with the settings you have mentioned.</p>
<p dir="auto">The problem is that PFsense is not routing this subnet through the  the IPsec tunnel in case of remote network has a public IP address.</p>
<p dir="auto">For all my tunnel with 10.x.y.z addresses it is working. But in case of 10X.x.y.z/25 I can see using <code>traceroute</code>it it goes directly to the ip address in the public internet.</p>
]]></description><link>https://forum.netgate.com/post/1147916</link><guid isPermaLink="true">https://forum.netgate.com/post/1147916</guid><dc:creator><![CDATA[admin_axx]]></dc:creator><pubDate>Mon, 15 Jan 2024 11:40:40 GMT</pubDate></item><item><title><![CDATA[Reply to redirect to PFsense IPsec tunnel endpoit which has public IP on Mon, 15 Jan 2024 11:28:57 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/admin_axx">@<bdi>admin_axx</bdi></a><br />
Directing a public IP range through the tunnel is generally the same as a private one.</p>
<p dir="auto">If it is a policy-based IPSec put 10X.x.y.z/25 into the remote network field in the phase 2 and at the remote site into the local network field. And then pfSense should route this subnet through the tunnel.</p>
]]></description><link>https://forum.netgate.com/post/1147915</link><guid isPermaLink="true">https://forum.netgate.com/post/1147915</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Mon, 15 Jan 2024 11:28:57 GMT</pubDate></item></channel></rss>