Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to NAT OpenVPN clients to BINATed IPSEC tunnel?

    Scheduled Pinned Locked Moved NAT
    4 Posts 2 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W Offline
      warpil
      last edited by

      I'm not sure if its NAT related … but its involved here for sure.

      I have some ipsec tunnel, where all my network NATed under my public IP and goes to remote network (BINAT).

      I want OpenVPN clients, that connects to me - also to be nat-ed (able to go to remote network) ... how to do this ?

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        You would need an additional Phase 2 where the OpenVPN subnet is included in the "local network" (before NAT)

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • W Offline
          warpil
          last edited by

          Ok, but pFsense not allowing me 2 2nd phase with same BINAT ip addresses for masq.
          I mean not allow to be both of them online, as on screenshot:

          How i include openvpn to local network?

          Or you mean - setup clients of OpenVPN with address of LAN ?

          1 Reply Last reply Reply Quote 0
          • W Offline
            warpil
            last edited by

            So far - i've just made openVPN as neighbor LAN (LAN - 30.0/24, openvpn 31.0/24), and for BINAT i used 30.0/23 mask - so it working.
            But i'm not sure if this right solution =)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.