Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    P2P one mains site and multiple clients

    Scheduled Pinned Locked Moved OpenVPN
    4 Posts 2 Posters 191 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • PierreFrenchP
      PierreFrench
      last edited by

      Hello,
      My setup is the following:
      I have a Mains site with a pfsense
      I have 5 remote site each with a pfsense
      I need to have P2P between each remote site ans the main site and no communication between remote sites.
      If I understand correctly and if i want to keep the P2P shared key set up, does it mean that I have to create 5 independant servers on the mains site, each one serving one an only one remote site?
      Is that right?
      Thanks
      Pierre

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @PierreFrench
        last edited by

        @PierreFrench
        Shared key is deprecated and shouldn't be used anymore. You should go with TLS instead,

        You can do this with a single server as well. Just restrict the access with a proper firewall rule on the VPN Interface.
        Remember to create client specific override for each.

        PierreFrenchP 1 Reply Last reply Reply Quote 0
        • PierreFrenchP
          PierreFrench @viragomann
          last edited by

          @viragomann
          Thanks for your answer
          If It keep shre key is beacuse it is simple and I don't need a top level security on that.
          Regarding the second part of your answer regarding rules etc.. Can you please expand a bit on that ?
          I am not getting it
          Thanks

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @PierreFrench
            last edited by

            @PierreFrench
            Shared key is deprecated, as mentioned, and I didn't use it for years.
            So I don't know if and how client specific overrides and the client side LAN routing work with it.
            I think, it should if xou state the correct client name and the respective remote networks.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.