Howto force one public ip over ipsec to go out to the internet at the other end



  • I have 2 sites connect over a IPsec tunnel. Site A and Site B. I have a website that I need to access but it only allows me to access it from Site A's Wan IP. How can I route traffic from Site B through to Site A's Wan interface Just for this one site. But all other lan to internet traffic needs to go out site A and B's Wan interface respectively.

    thank you


  • Rebel Alliance Developer Netgate

    Add a Phase 2 entry on both sides that covers the path from Site B's LAN to the IP address or subnet of the web site.
    Then make sure Site A's outbound NAT rules cover the LAN subnet at Site B.


Log in to reply