• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Official, Up-to-Date Method for Extending Subnet?

Scheduled Pinned Locked Moved OpenVPN
1 Posts 1 Posters 673 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    mevans336
    last edited by May 24, 2014, 4:07 PM

    I am running pfSense 2.1.3 and I'm looking for an official, up-to-date method for creating a site-to-site VPN to extend a subnet. It seems like there is a lot of discrepancy on how to do this and it seems like the process has changed from 1.x to 2.x to 2.1.

    Can anyone add to the procedure below so we can compile a proper procedure?

    Site 1:

    • Create a New OpenVPN Server Instance

    • Server Mode: Peer to Peer (Shared Key)

    • Device Mode: tap

    • Description: Layer 2 Bridge

    • Set IPv4 Tunnel Network to Unused Subnet

    • Save

    • Re-open the Server Instance and Copy the Shared TLS Key

    • Interfaces - Assign

    • Click +

    • Choose Layer 2 Bridge from Dropdown

    • Click Save

    • Click Interface Name

    • Check Enable Interface

    • Click Save, Apple Changes

    • Click Interfaces - Assign - Bridges

    • Click +

    • Select LAN and OPTx Interface

    • Enter Description - Save

    • Firewall - Rules - OPTx

    • Create Basic Allow All Rule (IPV4, Protocol: Any)

    • Save - Apply Changes

    Site 2:

    • Create a New OpenVPN Client Instance

    • Server Mode: Peer to Peer (Shared Key)

    • Device Mode: tap

    • Enter Server Host for Site 1

    • Enter Description

    • Paste Shared key from Site 1

    • IPv4 Tunnel Network: Same as Site 1

    • Interfaces - Assign - Click +

    • Choose tap1 interface from Dropdown

    • Click Save

    • Click Interface Name

    • Check Enable Interface - Save - Apply Changes

    • Click Interfaces - Assign - Bridges

    • Click +

    • Choose LAn and OPTx Interface

    • Enter Description - Save

    • Firewall - Rules - OPTx

    • Create Basic Allow All Rule (IPV4, Protocol: Any)

    • Save - Apply Changes

    That should be it for the pfSense config, correct? What about a sample configuration for a client behind each pfSense server?

    1 Reply Last reply Reply Quote 0
    1 out of 1
    • First post
      1/1
      Last post
    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
      This community forum collects and processes your personal information.
      consent.not_received