• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Multiple IPSec Tunnel with same LAN - NAT possible?

Scheduled Pinned Locked Moved IPsec
4 Posts 2 Posters 1.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    JeGr LAYER 8 Moderator
    last edited by Jul 4, 2014, 6:00 AM

    Morning everyone,

    situation is this: Customer has a central IPsec site with Juniper SRX and wants to connect multiple small offices to this. As he has no control over the offices and they all have "default DSL lines with dumb routers" they are likely to often have the same local LAN like 192.168.0.x or .1.x.
    Now he wants to ship small pfSense boxes out, that either replace the default router or are set up behind it (let the dumb device do PPPoE and forward everything to the pfSense behind).

    Question is: can I easily rewrite the local addresses from the offices (192.168.x.x) via NAT on the IPsec Interface? Idea is to use an address of an uncritical segment like 10.234.5.x to outbound-NAT all offices, so the packages that arrive at the concentrator (Juniper) can be mapped to the corresponding IPSec Tunnels.

    Backtraffic (central to branches) is NOT necessary. All that has to work is that the branches can access a defined server at central via their corresponding IPSec tunnels.

    Is it as easy as define an outbound NAT on the IPsec interface? Or has the NAT address to be used (10.234.xy) be defined as a virtual IP somewhere so the packets coming back are accepted?

    Thanks for giving it some thought,
    Jens

    Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

    If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Jul 7, 2014, 3:33 PM

      NAT+IPsec works fine and is easy on pfSense 2.1 and later.

      In the phase 2 settings, define the NAT network under the local Phase 2 network and that's all you need to do.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • J
        JeGr LAYER 8 Moderator
        last edited by Jul 8, 2014, 3:39 PM

        Seems there are problems with the remote side (Juniper), as it is saying that SA is only one-way. The way back to the branches isn't recognized as it seems pfSense sends it with the NAT IP in it and Juniper VPN (as well as Cisco) isn't able to make use of that.

        Any thoughts how to do that correctly? Is it possible to annouce the back route with local net but rewrite it with NAT nonetheless?

        Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

        If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Jul 8, 2014, 5:15 PM

          The only setting on pfSense is the NAT address entry. People have used many:1 (e.g. LAN/24 -> NAT/32 ) for connecting to other gear before, including large vendors and systems such as Verizon/AT&T for cell network backend connections.

          If that doesn't work with the Juniper settings, there may be something else that needs set on the Juniper side. Otherwise, try using a /24 for the NAT address/network and not a many:1 type NAT setup.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received