<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenVPN user access to networks behind IPSEC tunnels]]></title><description><![CDATA[<p dir="auto">I need help with with OpenVPN users access to networks on the other side of IPSEC VPN tunnels.<br />
Currently, 50+ IPSEC VPN tunnels are established from VPN router on LAN (10.254.0.1), plan is to transfer them all to pfSense. Diagram:</p>
<p dir="auto"><img src="/assets/uploads/files/1767354384721-3194b992-6c6e-4c47-b6d5-cf9ed69cdeb5-image.png" alt="3194b992-6c6e-4c47-b6d5-cf9ed69cdeb5-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">With all IPSEC tunnels behind VPN router, on pfSense I have VPN router as gateway and static routes to all A, B and C private networks over VPN router. OpenVPN user's network 10.250.1.0/24 is NATed on pfSense LAN IP 10.254.0.15, all OpenVPN users can access all networks behing VPN router tunnels.</p>
<p dir="auto">I transfered one of those tunnels directly on pfSense, network behind it is 192.168.114.0/24, LAN users can access it, OpenPVN users cannot. How can I enable that?</p>
]]></description><link>https://forum.netgate.com/topic/199726/openvpn-user-access-to-networks-behind-ipsec-tunnels</link><generator>RSS for Node</generator><lastBuildDate>Thu, 11 Jun 2026 19:52:57 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/199726.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 02 Jan 2026 11:51:59 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to OpenVPN user access to networks behind IPSEC tunnels on Mon, 05 Jan 2026 16:13:45 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ivica.glavocic">@<bdi>ivica.glavocic</bdi></a> Check out this article from the documentation, <a href="https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/assign.html" target="_blank" rel="noopener noreferrer nofollow ugc">Assigning OpenVPN Interfaces</a>. That's one way to get OVPN traffic onto an interface that can then be NAT'ed to/from.</p>
<p dir="auto">(This confusingly-named subsection, <a href="https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/firewall-rules.html#allowing-traffic-over-openvpn-tunnels" target="_blank" rel="noopener noreferrer nofollow ugc">Allowing traffic over OpenVPN Tunnels</a>, then becomes relevant, too.)</p>
]]></description><link>https://forum.netgate.com/post/1234727</link><guid isPermaLink="true">https://forum.netgate.com/post/1234727</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Mon, 05 Jan 2026 16:13:45 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN user access to networks behind IPSEC tunnels on Mon, 05 Jan 2026 16:08:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> said in <a href="/post/1234722">OpenVPN user access to networks behind IPSEC tunnels</a>:</p>
<blockquote>
<p dir="auto">So yes, 'Manual Outbound NAT' 'Mode' will allow you to translate OVPN traffic to the LAN (or the WAN) interface address, which traffic will then follow the system routing table I believe. Inbound OVPN traffic NAT'ed to the LAN (or the WAN) interface should be able to 'find' any configured IPsec tunnels that way. And you would not need to touch the remote side of any IPsec tunnels.</p>
</blockquote>
<p dir="auto">That's what I thought, but looks like traffic goes directly from OpenVPN tunnel network to IPSEC VPN tunnel and is not NAT-ed, although there is a manual outbound NAT rule for OpenVPN network to pfSense LAN IP.</p>
<p dir="auto">I had an idea to use policy routing on OpenVPN interface, but what gateway do I put there? IPSEC tunnels are policy based.</p>
]]></description><link>https://forum.netgate.com/post/1234725</link><guid isPermaLink="true">https://forum.netgate.com/post/1234725</guid><dc:creator><![CDATA[ivica.glavocic]]></dc:creator><pubDate>Mon, 05 Jan 2026 16:08:23 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN user access to networks behind IPSEC tunnels on Mon, 05 Jan 2026 15:53:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ivica.glavocic">@<bdi>ivica.glavocic</bdi></a> I understand. I did become momentarily confused by your diagram.</p>
<p dir="auto">So yes, 'Manual Outbound NAT' 'Mode' will allow you to translate OVPN traffic to the LAN (or the WAN) interface address, which traffic will then follow the system routing table I believe. Inbound OVPN traffic NAT'ed to the LAN (or the WAN) interface should be able to 'find' any configured IPsec tunnels that way. And you would not need to touch the remote side of any IPsec tunnels.</p>
]]></description><link>https://forum.netgate.com/post/1234722</link><guid isPermaLink="true">https://forum.netgate.com/post/1234722</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Mon, 05 Jan 2026 15:53:17 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN user access to networks behind IPSEC tunnels on Mon, 05 Jan 2026 15:46:00 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> said in <a href="/post/1234716">OpenVPN user access to networks behind IPSEC tunnels</a>:</p>
<blockquote>
<p dir="auto">Why would you need to do this? What would that IPsec configuration look like? What does that mean, "IPSEC [sic] VPN tunnel terminated on same pfSense"?</p>
</blockquote>
<p dir="auto">Look at the diagram, on "VPN router" I have 50+ configured VPN tunnels that will in the future be transfered (terminated) on pfSense. All of those tunnels are configured with only my LAN subnet in phase 2, now I have to add OpenVPN subnet in every one of them and I don't control all remote VPN endpoints.</p>
<p dir="auto">If I NAT OpenVPN subnet to pfSense LAN address and then redirect that traffic to IPSEC VPN tunnel terminated on pfSense, I won't have to reconfigure those tunnels (add OpenVPN subnet to every tunnel).</p>
]]></description><link>https://forum.netgate.com/post/1234718</link><guid isPermaLink="true">https://forum.netgate.com/post/1234718</guid><dc:creator><![CDATA[ivica.glavocic]]></dc:creator><pubDate>Mon, 05 Jan 2026 15:46:00 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN user access to networks behind IPSEC tunnels on Mon, 05 Jan 2026 15:38:36 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ivica.glavocic">@<bdi>ivica.glavocic</bdi></a> said in <a href="/post/1234708">OpenVPN user access to networks behind IPSEC tunnels</a>:</p>
<blockquote>
<p dir="auto">NAT incoming OpenVPN traffic to pfSense LAN interface and then send it trough IPSEC VPN tunnel terminated on same pfSense.</p>
</blockquote>
<p dir="auto">Why would you need to do this? What would that IPsec configuration look like? What does that mean, "IPSEC [sic] VPN tunnel terminated on same pfSense"?</p>
]]></description><link>https://forum.netgate.com/post/1234716</link><guid isPermaLink="true">https://forum.netgate.com/post/1234716</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Mon, 05 Jan 2026 15:38:36 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN user access to networks behind IPSEC tunnels on Mon, 05 Jan 2026 15:01:00 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> said in <a href="/post/1234701">OpenVPN user access to networks behind IPSEC tunnels</a>:</p>
<blockquote>
<p dir="auto">I <em>think</em> you mean 'NAT incoming OVPN traffic to WAN interface so it can follow configured static routing to "VPN router" (i.e., <code>10.254.0.1</code>).'</p>
</blockquote>
<p dir="auto">I meant NAT incoming OpenVPN traffic to pfSense LAN interface and then send it trough IPSEC VPN tunnel terminated on same pfSense.</p>
]]></description><link>https://forum.netgate.com/post/1234708</link><guid isPermaLink="true">https://forum.netgate.com/post/1234708</guid><dc:creator><![CDATA[ivica.glavocic]]></dc:creator><pubDate>Mon, 05 Jan 2026 15:01:00 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN user access to networks behind IPSEC tunnels on Mon, 05 Jan 2026 14:44:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ivica.glavocic">@<bdi>ivica.glavocic</bdi></a> said in <a href="/post/1234687">OpenVPN user access to networks behind IPSEC tunnels</a>:</p>
<blockquote>
<p dir="auto">Is there a way to NAT incoming OpenVPN traffic from 10.250.0.0/22 subnet to firewall NAT IP 10.254.0.15 and then redirect it trough IPSEC tunnel on pfSense?</p>
</blockquote>
<p dir="auto">Probably—using '<a href="https://docs.netgate.com/pfsense/en/latest/nat/outbound.html#outbound-nat-mode" target="_blank" rel="noopener noreferrer nofollow ugc">Manual Outbound NAT' 'Mode'</a>.</p>
<p dir="auto">I <em>think</em> you mean 'NAT incoming OVPN traffic to WAN interface so it can follow configured static routing to "VPN router" (i.e., <code>10.254.0.1</code>).'</p>
]]></description><link>https://forum.netgate.com/post/1234701</link><guid isPermaLink="true">https://forum.netgate.com/post/1234701</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Mon, 05 Jan 2026 14:44:25 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN user access to networks behind IPSEC tunnels on Mon, 05 Jan 2026 13:23:02 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> found a source of the problem - on the remote side I added route trough IPSEC VPN tunnel for my OpenVpn net 10.250.0.0/22, after that I got a response from remote 192.168.114.0/24 network.</p>
<p dir="auto">Since I have 50+ active IPSEC tunnels, adding OpenVPN subnet in all of them is going to be difficult specially since I don't control routers on the other side.</p>
<p dir="auto">Is there a way to NAT incoming OpenVPN traffic from 10.250.0.0/22 subnet to firewall NAT IP 10.254.0.15 and then redirect it trough IPSEC tunnel on pfSense?</p>
]]></description><link>https://forum.netgate.com/post/1234687</link><guid isPermaLink="true">https://forum.netgate.com/post/1234687</guid><dc:creator><![CDATA[ivica.glavocic]]></dc:creator><pubDate>Mon, 05 Jan 2026 13:23:02 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN user access to networks behind IPSEC tunnels on Mon, 05 Jan 2026 12:51:27 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> as visible on diagram, OpenVPN user gets IP 10.250.1.2/22, server has 10.250.0.1/22, traffic looks like it's allowed in firewall logs:</p>
<p dir="auto"><img src="/assets/uploads/files/1767617464484-370cf81c-c7c7-41f3-82d4-047172dc702a-image.png" alt="370cf81c-c7c7-41f3-82d4-047172dc702a-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/1234685</link><guid isPermaLink="true">https://forum.netgate.com/post/1234685</guid><dc:creator><![CDATA[ivica.glavocic]]></dc:creator><pubDate>Mon, 05 Jan 2026 12:51:27 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN user access to networks behind IPSEC tunnels on Mon, 05 Jan 2026 12:21:33 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ivica.glavocic">@<bdi>ivica.glavocic</bdi></a> What's happening to OVPN traffic arriving on the WAN interface at this point? How does it appear?</p>
]]></description><link>https://forum.netgate.com/post/1234682</link><guid isPermaLink="true">https://forum.netgate.com/post/1234682</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Mon, 05 Jan 2026 12:21:33 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN user access to networks behind IPSEC tunnels on Mon, 05 Jan 2026 10:07:58 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> said in <a href="/post/1234484">OpenVPN user access to networks behind IPSEC tunnels</a>:</p>
<blockquote>
<p dir="auto">You may still need a NAT rule on WAN interface to translate incoming OVPN traffic to the applicable IPsec interface on pfSense.</p>
</blockquote>
<p dir="auto">I excluded subnet 192.168.114.0/24 from static routes. Can you please give me an example of NAT rule on WAN interface to translate incoming OVPN traffic to the applicable IPsec interface on pfSense? Still no reply from devices on that subnet, 10.250.0.0/22 is included in phase 2 of IPSEC tunnel, mode is Tunnel, not Routed.</p>
]]></description><link>https://forum.netgate.com/post/1234675</link><guid isPermaLink="true">https://forum.netgate.com/post/1234675</guid><dc:creator><![CDATA[ivica.glavocic]]></dc:creator><pubDate>Mon, 05 Jan 2026 10:07:58 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN user access to networks behind IPSEC tunnels on Fri, 02 Jan 2026 14:12:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ivica.glavocic">@<bdi>ivica.glavocic</bdi></a> said in <a href="/post/1234483">OpenVPN user access to networks behind IPSEC tunnels</a>:</p>
<blockquote>
<p dir="auto">I hoped that IPSEC VPN tunnel on pfSense, will have precedence over those status routes, it does not.</p>
</blockquote>
<p dir="auto">That's correct. 'Precedence' is not a technical term.</p>
<p dir="auto">The most obvious solution would be to exclude subnet <code>192.168.114.0/24</code> from your static routes. There's obviously a couple ways to do that.</p>
<p dir="auto">You may still need a NAT rule on WAN interface to translate incoming OVPN traffic to the applicable IPsec interface on pfSense.</p>
]]></description><link>https://forum.netgate.com/post/1234484</link><guid isPermaLink="true">https://forum.netgate.com/post/1234484</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Fri, 02 Jan 2026 14:12:25 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN user access to networks behind IPSEC tunnels on Fri, 02 Jan 2026 14:07:32 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> said in <a href="/post/1234482">OpenVPN user access to networks behind IPSEC tunnels</a>:</p>
<blockquote>
<p dir="auto">This seems like the culprit. If all inbound OVPN traffic has its destination NAT'ed to pfSense's LAN address, then that traffic will then follow the static routes configured to send it downstream to "VPN router".</p>
</blockquote>
<p dir="auto">Correct, all traffic for IPSEC VPN tunnel 192.168.114.0/24 on pfSense goes trough "VPN router".</p>
<blockquote>
<p dir="auto">Can you be more specific and/or show what you mean by "static routes to all A, B and C private networks"?</p>
</blockquote>
<p dir="auto">All static routes for private networks are routed via "VPN router":<br />
10.255.255.255  /8<br />
172.31.255.255  /12<br />
192.168.255.255 /16</p>
<p dir="auto">I hoped that IPSEC VPN tunnel on pfSense, will have precedence over those status routes, it does not.</p>
]]></description><link>https://forum.netgate.com/post/1234483</link><guid isPermaLink="true">https://forum.netgate.com/post/1234483</guid><dc:creator><![CDATA[ivica.glavocic]]></dc:creator><pubDate>Fri, 02 Jan 2026 14:07:32 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN user access to networks behind IPSEC tunnels on Fri, 02 Jan 2026 13:41:38 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ivica.glavocic">@<bdi>ivica.glavocic</bdi></a> said in <a href="/post/1234473">OpenVPN user access to networks behind IPSEC tunnels</a>:</p>
<blockquote>
<p dir="auto">OpenVPN user's network 10.250.1.0/24 is NATed on pfSense LAN IP 10.254.0.15</p>
</blockquote>
<p dir="auto">This seems like the culprit. If all inbound OVPN traffic has its destination NAT'ed to pfSense's LAN address, then that traffic will then follow the static routes configured to send it downstream to "VPN router".</p>
<p dir="auto">Can you be more specific and/or show what you mean by "static routes to all A, B and C private networks"?</p>
]]></description><link>https://forum.netgate.com/post/1234482</link><guid isPermaLink="true">https://forum.netgate.com/post/1234482</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Fri, 02 Jan 2026 13:41:38 GMT</pubDate></item></channel></rss>