Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Configuring a VPN endpoint behind another firewall

    Scheduled Pinned Locked Moved General pfSense Questions
    2 Posts 2 Posters 875 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      drogo
      last edited by

      I currently have a ubiquity EdgeRouter Lite as my main firewall at home, and there are 3 openvpn tunnels running on it.

      I'm going to be added a few more tunnels (~4) and was thinking that it might be better to use pfsense on a VM as a VPN endpoint behind the ERL. Then I could provide more RAM and CPU as needed to keep things flowing smoothly.

      Is there a recommended setup for something like this? I won't be needing the firewalling, so I was planning to completely disable that, but there won't be two separate subnets for the interfaces, so should I be looking into some kind of one armed router config with virtual interfaces? I'm also not sure about openvpn vs. ipsec, but I figured that I could perform some testing to find out what's better on that front.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        For a VPN router you only need one interface. The "wan" can exist on your current LAN. The edge router would forward in the VPN port(s) to pfSense, and the edge router would also have a static route pointing the VPN subnet(s) at pfSense. That's really all there is to it.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.