<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPSEC do not route trafic coming from other IP&#x27;s (not local subnet but from a subnet connected with a router with local)]]></title><description><![CDATA[<p dir="auto">Hi,<br />
I am new on pfSense and IPSEC and now I am stuck for few days trying to configure all I need.</p>
<p dir="auto">I have next config:<br />
my local net: 10.10.0.x with gw 10.10.0.254 (used for internet connection)<br />
on the gw i have also a openvpn server and clients have ip's in 10.8.0.x and gw for them on 10.8.0.1</p>
<p dir="auto">I installed pfSense for IPSEC and in next time want to move slowly all services form old router (ClearOS) on pfSense.<br />
So I have pfsense on 10.10.0.200 and remote net is 10.30.0.x.<br />
All routing between 10.10.0 and 10.30.0 are working ok.<br />
The same from 10.8 to 10.10<br />
But when I try ping from 10.8 ip to IPSEC ip, pfsense receive on xn0 interface the ICMP packet but do not pass to enc0. I receive TTL expired in transit.</p>
<p dir="auto">If i ping from 10.30.0 ip to 10.8.0.1, packet go to destination and when return stuck in the same place, on  xn0 interface of pfsense.<br />
As I told, ping from 10.8 to 10.10.0.200 is ok. Also ping from 10.30 to 10.0.0.254 is ok.<br />
I do not understand why pfsense do not want to route a packet to 10.30 comming from 10.8</p>
<p dir="auto">Any advice is welcome.<br />
Thanks</p>
]]></description><link>https://forum.netgate.com/topic/195764/ipsec-do-not-route-trafic-coming-from-other-ip-s-not-local-subnet-but-from-a-subnet-connected-with-a-router-with-local</link><generator>RSS for Node</generator><lastBuildDate>Tue, 17 Mar 2026 03:21:48 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/195764.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 28 Dec 2024 22:20:31 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IPSEC do not route trafic coming from other IP&#x27;s (not local subnet but from a subnet connected with a router with local) on Sun, 29 Dec 2024 09:58:53 GMT]]></title><description><![CDATA[<p dir="auto">Hi,<br />
you may try do reboot the pfsense, the routing table is sometimes a little bit weird.</p>
]]></description><link>https://forum.netgate.com/post/1200901</link><guid isPermaLink="true">https://forum.netgate.com/post/1200901</guid><dc:creator><![CDATA[pete35]]></dc:creator><pubDate>Sun, 29 Dec 2024 09:58:53 GMT</pubDate></item></channel></rss>