Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Possible to use pfsense just as a vpn gateway without it being main firewall?

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 2 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      ghurty
      last edited by

      I am planning on experimenting with pfsense.

      I have an Vmware vshpere system running esx.

      I found some decent guides to working with it as a virtual machine, which I am going to start off with.

      But first, I would like to use it to help me administer the vshere securely.

      When I install it on the virtual machine, can I then use it as a VPN access point so I can connect a remote 7 machine into the local network?

      At this point, I would not be using the pfsense for anything else, as I would be slowly enabling that.

      Thank you

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        Yes this should be possible without problem.
        Make sure that you leave the LAN unconnected and use the WAN to connect to.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • G
          ghurty
          last edited by

          Would I have to setup any port forwarding on the real router (wrt160n)?

          Also if LAN is not connected, how would the remote machine be able to access the local network to control the vSphere?

          Thanks

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            Yes you would need portforwards.
            Also you would need static routes on your existing router, telling it over which IP the VPNs are reachable.

            I didn't mean disconnect in the sense of not existing, but that you connect your existing network to the WAN.
            Something like this:

            |–-------------------------------------|
            inet-----router-----|----virtual_WAN                        |
                                    |                |                            |
                                    |        ---------------                  |
                                    |        |  pfSense    |                  |
                                    |        ----------------                  |
                                    |                |                            |
                                    |            virtual_LAN                  |
                                    |                                              |
                                    ----------------------------------------

            Basically, the WAN is the interface to which your VPN clients connect to, and the WAN is the interface which is used to talk to the rest of your existing network.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.