Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Site to Site with routing of trafic to extra vpn router

    Scheduled Pinned Locked Moved Routing and Multi WAN
    7 Posts 5 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      affe
      last edited by

      Hello
      I have a settup with a ipsec site to site <site 24="" a="" 10.11.0.0=""><site 24="" b="" 10.11.1.0="">and this works flawless, now I need to route some specific trafic in both sites to a new gateway that creates a vpn tunnel to a center and they dont whant to involve my routers, this is placed on 10.11.0.3, I put in the static routing on site A and on site B and on site A the routing works but doing a trace from site B shows that it go straight out on  internet. Im guessing I have done something wrong just dont know what.

      Something I notices is that in Site B under "Diagnostics > Routes" the route turns up with 10.11.1.0.3.
      ![IPSEC tunnels.png](/public/imported_attachments/1/IPSEC tunnels.png)
      ![IPSEC tunnels.png_thumb](/public/imported_attachments/1/IPSEC tunnels.png_thumb)</site></site>

      1 Reply Last reply Reply Quote 0
      • A Offline
        affe
        last edited by

        Is there anyone who knows how to do this? If there is some additional information needed that could help understanding my setup then ask away.

        1 Reply Last reply Reply Quote 0
        • D Offline
          darnitol
          last edited by

          Can you post screenshots of the routing pages in Sites A and B?

          1 Reply Last reply Reply Quote 0
          • A Offline
            affe
            last edited by

            In the end I decided to leave ipsec and use openvpn instead. I just forgot to close the tread.

            1 Reply Last reply Reply Quote 0
            • C Offline
              craigduff
              last edited by

              The answer for me.. Would be to do a route add command onto pfsense and tell it where to route the traffic. And point it the new gateway. Sorry for the late reply.

              Kind Regards,
              Craig

              1 Reply Last reply Reply Quote 0
              • GruensFroeschliG Offline
                GruensFroeschli
                last edited by

                With OpenVPN yes.
                But this doesn't really work with IPSEC.

                We do what we must, because we can.

                Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                1 Reply Last reply Reply Quote 0
                • U Offline
                  Umberto
                  last edited by

                  Routing over an ipsec tunnel won't work.
                  What you can do is make a ipsec tunnel in transport mode and put a GRE tunnel on top, then you can route whatever you want.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.