Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Does not have a public address and is behind NAT

    Scheduled Pinned Locked Moved IPsec
    4 Posts 2 Posters 27 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      testsia
      last edited by

      Hello I have two pfsense. One of them has a public IP address. The second one does not have a public address and is behind NAT. I need to connect them using IPsec. I have previously worked only with openvpn and there are no such problems. Is this possible? I can't get the tunnel to install. Снимок экрана 2025-07-21 в 10.43.54.png What should I specify in the remote host? zeros don't work, tried internal IP but the tunnel doesn't go up. Thanks for your help

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @testsia
        last edited by

        @testsia said in Does not have a public address and is behind NAT:

        What should I specify in the remote host?

        See here : IPsec Site-to-Site VPN Example with Pre-Shared Keys so the other side, or Remote Gateway must be the IP or host name of that end point.

        You said that one of the end point "Does not have a public address .... " and after reading the instructions, I tend to say : No IPSEC for you (I hope to be wrong of course).

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        T 2 Replies Last reply Reply Quote 0
        • T
          testsia @Gertjan
          last edited by

          @Gertjan said in Does not have a public address and is behind NAT:

          instructions
          I followed all of these instructions. But in the example there are two public IPs, but I only have one. I understand that it is not possible to bypass the restriction. It is a pity.

          1 Reply Last reply Reply Quote 0
          • T
            testsia @Gertjan
            last edited by

            @Gertjan said in Does not have a public address and is behind NAT:

            Managed to solve the problem.

            1. You need to enter any fictitious name and your external IP in DNS Resolver. I entered both my pfsense on one and the second pfsense.Снимок экрана 2025-07-21 в 15.38.01.png
            2. In phase 1 you need to register.
              Снимок экрана 2025-07-21 в 15.39.32.png
              After which everything started working.
            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.