Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [SOLVED]IpSec and internet

    Scheduled Pinned Locked Moved IPsec
    3 Posts 2 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jtn
      last edited by

      Hello!!!
      There is a network:

      Lan 172.19.60.0/24 (Office)  –-------WAN XX.XX.XX.XX------------ Internet
                                            |
                                            ---------OPT XX.XX.XX.XX ----------- IPSec ------------------ WAN XX.XX.XX.XX ---------LAN 172.19.49.0/24
                                                                                |
                                                                                ----------- IPSec------------------- WAN XX.XX.XX.XX ---------LAN 172.19.50.0/24

      Networks which are connected through IPSec are visible, pings go in both sides. How to distribute the Internet from interface WAN of network Office for networks 172.19.49.0/24 and 172.19.50.0/24.
      Everywhere are established PFSense

      1 Reply Last reply Reply Quote 0
      • P
        psylo
        last edited by

        Well… The easiest way to do that is to use a proxy on main site (172.19.60.0/24).

        Now, without a proxy:

        • you will have to permit all traffic to go in the IPSEC (172.19.49.0/24 <-> any and 172.19.50.0/24 <-> any).
        • you will have to NAT those 2 networks on the pfSense in the main office.

        Hope this helps.

        [EDIT]: I've read in another post the NAT & IPSec is supported only in v2.0 (and it's not fully supported: it needs again some testing).

        1 Reply Last reply Reply Quote 0
        • J
          jtn
          last edited by

          Thanks for your help for me!

          I installed a proxy server on the network 172.19.60.0/24 and provide all customers with access through it.
          ;) ;) ;)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.