Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How do I tunnel a few disjointed networks one way through a tunnel?

    Scheduled Pinned Locked Moved IPsec
    3 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      wil
      last edited by

      Hi

      To get straight in to it… I have an IPSec tunnel between two networks.

      One site is using 192.168.0.x/21 and the other site is using 192.168.10.x/24 for their private IP range.

      When setting up each of the phase 2 entries, I simply used the above as the local/remote entries - and it works great.

      I now need (in addition to the above) two completely different public IP ranges to be routed to one side of the tunnel so that all requests from one side will be routed across the tunnel.

      I tried the "None" option on local range (which I now know is a bug - http://redmine.pfsense.org/issues/2812#change-10754 ), along with trying to use a few different options, but, I just can't get it to work and the phase two won't establish.

      I have been looking in the logs and just can't figure out what is wrong.

      Anyone know what I have to do?

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Cover the exact path (src/dst) the traffic needs to take from either side.

        <local network="">… <public ip="" block="">and

        <public ip="" block="">... <local network=""></local></public></public></local>

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • W
          wil
          last edited by

          So, it is ok for local network to be duplicated in rules?

          I did try this, but saw that one of the errors at one point was "duplicate rule" or similar in the logs, so I figured it was not meant to be like that.

          … I will try again shortly.

          Thanks,

          Wil

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.