Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Simple policy route

    Scheduled Pinned Locked Moved Routing and Multi WAN
    4 Posts 2 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • X
      xxxomxxx
      last edited by

      Hi all

      i'd like to route a destination ip over ipsec to my other gateway. I'm used to do it over the policy route with a zywall 5 - but i just cant find anything in the pfsense that resembles this. I have seen that you can add a gateway in a firewall rule, but i can only choose default. Can i define my other gateways internal ip adress somewhere so i get them in the drop down list??

      how is it done - if it can be done?

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        There isn't any way in the firewall rules to apply that kind of policy for IPsec.

        If you make the IP you want to go over IPsec the remote side of the IPsec phase 2 subnet, that would do the trick.

        This isn't so easy on 1.2.3, but on 2.0 you can just add an additional Phase 2 entry to match the traffic.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • X
          xxxomxxx
          last edited by

          thx, that might work. The problem there is that i can not specify single ip adresses so i would need to define a subnet of an external ip range โ€ฆ tricky...

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            On 2.0 you can do it by either picking 'address' for the type, or just enter x.x.x.x/32 for a single IP. On 1.2.3 just do x.x.x.x/32.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.