Simple OpenVPN NAT question

  • Hi all,

    I have two OpenVPN clients VPN'd into a server at HQ:

    Site A -
    Site B -

    HQ can ping both sites and both sites can ping each other so the VPN is all good.

    However, I need to apply some outbound NAT so that HQ can reach both Site A and Site B on a new translated IP range: for Site A for Site B

    It's been a while since i've played with pfSense and I did do this successfully some time back my lab setup but can't for the life of me remember how I did it!

    Any advice would be a real help.


  • Rebel Alliance Developer Netgate

    The NAT would have to be done on the client side. Put 1:1 NAT entries on the OpenVPN interface on the client routers, external subnet = your translated subnet, internal subnet = site a/b real LAN subnet

  • Thanks Jim, would I also need to add an iroute and 'route' for the translated subnet on the server that they are VPN'd into?

  • Rebel Alliance Developer Netgate

    Yes, you'd route to the translated subnet

