<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Control P2 local network proposal with nat before ipsec config]]></title><description><![CDATA[<p dir="auto">Hey gang..</p>
<p dir="auto">I just upgraded from 2.1.5 to 2.2 and I've been going through some IPSec pain ever since..</p>
<p dir="auto">I am connecting to a SonicWALL IPSec endpoint (unsure of the model number) and need to nat my private network to a specific 10.x netblock prior to IPSec.</p>
<p dir="auto">The endpoint is expecting my local network on P2 to be 10.2.63.0/29.  I have my P2 config'd in pfSense as such:<br />
  - Local Network:  type Net, address 10.0.0.0/8 (I need addresses in 10.1 and 10.2 to be nat'd for me)<br />
  - NAT network:  type Net, address 10.2.63.0/29 (this is what I need it nat'd to prior to IPSec)</p>
<p dir="auto">This works as expected, except that the SonicWALL is rejecting my P2 proposals.  Eventually it responds with one of its own, and it gets accepted and works for a while (until it needs to rekey), but any P2 proposal being sent from pfSense is not accepted.</p>
<p dir="auto">The combo of the above config generates the following in ipsec.conf:<br />
        leftsubnet = 10.2.63.0/29|10.0.0.0/8</p>
<p dir="auto">Is there any way to control the generation of this file so that it only includes the NAT network from the config, i.e. only 10.2.63.0/29?  I'm assuming that the sonicwall is seeing 10.0.0.0/8 and rejecting based on that.</p>
<p dir="auto">Or alternately, is there a better way to generate the NAT pf rule on the enc0 interface than to use the above configuration methodology?</p>
<p dir="auto">Thanks!</p>
<p dir="auto">Joe</p>
]]></description><link>https://forum.netgate.com/topic/79236/control-p2-local-network-proposal-with-nat-before-ipsec-config</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Apr 2026 10:26:46 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/79236.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 03 Feb 2015 20:37:56 GMT</pubDate><ttl>60</ttl></channel></rss>