Act as only responder IPSec tunnel endpoint
-
Hi all,
i'm ready to try pfSense in order to replace a not working configuration with a Netgear FVS338.Basically I have 17 remote router UMTS that have to tunnel each local network to my central network.
Central network behind Netgear (will be pfSense)
192.168.1.0
255.255.255.0Remote networks
10.0.xxx.0
255.255.255.0
with xxx from 1 to 17I have dynamic IPs on UMTS routers: Netgear permit to configure phase 1 as "Responder" in order to not specify remote gateway IP.
How can I do this with pfSense?
I can't go with mobile clients I suppose because I have to access remote local networks.
Thanks
-
Hi,
u need to use mobilconfig because umts networks are not reachable from external networks.
Example for 1 Site:
1. central pfsense:
gote system/usermanager
create usergroup eg. remoteaccess with privileges: User - VPN - IPsec xauth Dialincreate 17 user in usermanager with preshared keys eg. site1 - site17, add to group remoteaccess,
goto ipsec -> mobile clients -> enable ike mobile extension -> save
create phase 1
create phase 2create Firewallrule for each mobile subnet on ipsec tab
eg: allow any traffic from subnet eg. 10.0.1.0/24 to 192.168.1.0/24
or one for all: allow any traffic from subnet 10.0.0.0/19 to 192.168.1.0/24
data:image/s3,"s3://crabby-images/b4cd1/b4cd1e9a71fedacfcf2c5a36b68a2df0bd5119b8" alt="central_System User Manager.jpg"
data:image/s3,"s3://crabby-images/022f4/022f40bc334a6e0608043c5594711216038d1a32" alt="central_System User Manager.jpg_thumb"
data:image/s3,"s3://crabby-images/35cc5/35cc535bf81f50062913b33f1279ba8eff4fbfae" alt="central_IPsec Mobile.jpg"
data:image/s3,"s3://crabby-images/3c38e/3c38e89b9d360ce46769f7a3ba512ee083a41a36" alt="central_IPsec Mobile.jpg_thumb"
data:image/s3,"s3://crabby-images/e10c9/e10c97ac9eff9df80d2306aff87edeb2b4927908" alt="central_Phase 2.jpg"
data:image/s3,"s3://crabby-images/43707/4370712ee3af992ade9cb30d685197faf91a904a" alt="central_Phase 2.jpg_thumb"
data:image/s3,"s3://crabby-images/48c1f/48c1fb9b0f4479b889fbb97598f46bc87ddf5eb0" alt="central_IPsec Keys.jpg"
data:image/s3,"s3://crabby-images/d0379/d03796046361d57fe979349fd55f4d9c7205a7ac" alt="central_IPsec Keys.jpg_thumb" -
part 2:
umts pfsense:
create phase 1
my identifier: keyID tag = <user>preshared key = <userkey>create phase 2create ipsec firewallrule:
eg: allow any traffic from central subnet 192.168.1.0/24 to eg. 10.0.1.0/24
ping ur central pfsense lan ip, check ur ipsec logs
If ur umts routers are not pfsense u need to translate these settings. Umts routers need to support nat-t.
cya
data:image/s3,"s3://crabby-images/2c2c3/2c2c350b9fb8d5afb2c15bbd34b42fcf9637efc9" alt="umts_Phase 1.jpg"
data:image/s3,"s3://crabby-images/ba725/ba7259ed6e03ffa35d5869bc92cd54bc80ec76a2" alt="umts_Phase 1.jpg_thumb"
data:image/s3,"s3://crabby-images/9b73a/9b73a156996588d57e613b00ca50e8640dc6eaa4" alt="umts_Phase 2.jpg"
data:image/s3,"s3://crabby-images/740d0/740d026e5d02af8cd2ec43f43a0935e6d4414a05" alt="umts_Phase 2.jpg_thumb"</userkey></user>