Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN Server behind pfSense Firewall

    Scheduled Pinned Locked Moved NAT
    3 Posts 3 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      endy
      last edited by

      Hi
      I have searched for hours, but not found a solution. Im using a pfSense firewall for my lan. Inside this lan, im running a l2tp/ipsec vpn server, which is set up correct. But now i need to configure my pfSense box, to allow connections from the internet. I have forwarded udp port 500 and udp port 4500. Ass i read, i need to forward protocol 50(esp), but i dont know how to do this in pfsense. Or do i need to do some other forwardings / configurations? For testing, i have replaced the pfSense box with a linksys router / firewall, opened the ports and enabled ipsec passthrough, and so the connection to the vpn server from outside works. Now i need to know, what i need to configure on the pfSense box.

      I hope you can help me

      1 Reply Last reply Reply Quote 0
      • M
        muswellhillbilly
        last edited by

        You know that pfSense has an IPSec VPN tunnel built in already? Why run a separate system to accomplish something you can just run on one?

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Yeah don't understand this sort of setup either, its always best to put the vpn connection at the actual edge, not forwarded to some box inside behind a nat.

          But to answer your question directly, just forward ESP which protocol 50.  Don't you want 51 as well AH?

          protocol50.png
          protocol50.png_thumb

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.