Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Simple OpenVPN NAT question

    Scheduled Pinned Locked Moved OpenVPN
    4 Posts 2 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jamesc
      last edited by

      Hi all,

      I have two OpenVPN clients VPN'd into a server at HQ:

      Site A - 172.16.20.0/24
      Site B - 172.16.30.0/24

      HQ can ping both sites and both sites can ping each other so the VPN is all good.

      However, I need to apply some outbound NAT so that HQ can reach both Site A and Site B on a new translated IP range:

      192.168.20.0/24 for Site A
      192.168.30.0/24 for Site B

      It's been a while since i've played with pfSense and I did do this successfully some time back my lab setup but can't for the life of me remember how I did it!

      Any advice would be a real help.

      James

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        The NAT would have to be done on the client side. Put 1:1 NAT entries on the OpenVPN interface on the client routers, external subnet = your translated subnet, internal subnet = site a/b real LAN subnet

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • J
          jamesc
          last edited by

          Thanks Jim, would I also need to add an iroute and 'route' for the translated subnet on the server that they are VPN'd into?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            Yes, you'd route to the translated subnet

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.