<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPSEC is connected but one-way traffic - NAT problem]]></title><description><![CDATA[<p dir="auto">I have upgraded both hardware and pfSense software to 2.1.4 - and I took the opportunity to do a fresh config from scratch to clear out loads of cruft that had accumulated.  But now I'm not recreating the IPSEC VPN entirely correctly for some reason.</p>
<p dir="auto">my setup:</p>
<p dir="auto">LAN 192.168.1.1 &lt;–&gt; pfsense wan 75.nn.nn.nn &lt;--&gt; internet &lt;--&gt; datacenter IPSec &lt;--&gt; VM Server 192.168.2.1</p>
<p dir="auto">Note that data center / VM provider manages IPSec on their end, and all this was working before I changed my side of the equation.</p>
<p dir="auto">My IPSec configuration appears to be OK, and tunnel established, etc.  Datacenter tech confirms he is showing UP/UP on his side also.  Traffic originating at datacenter can route to LAN OK - i.e., from 192.168.2.1, I can fetch a webpage hosted on 192.168.1.100.</p>
<p dir="auto">However, reverse traffic is not working.</p>
<p dir="auto">Datacenter tech advises that all the request from my side of the tunnel are dropping because they originate at 75.nn.nn.nn, instead of a 192.168.1.n address.</p>
<p dir="auto">So, I am NAT'ing when I should not be - or rather, I am NAT'ing to the wrong interface address (pfSense public IP) instead of using PFSense LAN.</p>
<p dir="auto">Any help?  Thanks!</p>
]]></description><link>https://forum.netgate.com/topic/72272/ipsec-is-connected-but-one-way-traffic-nat-problem</link><generator>RSS for Node</generator><lastBuildDate>Sat, 18 Jul 2026 18:23:28 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/72272.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 09 Aug 2014 16:59:42 GMT</pubDate><ttl>60</ttl></channel></rss>