IPSec: NAT for every local Subnet?



  • Hi,

    we plan to change from OpenBSD to Pfsense. We have

    6x Local Subnets (like 192.168.x.x/24)
    10x IPSec Phase 1
    18x IPSec Phase 2 (like 10.200.0.0/16, 192.168.x.x/24)

    NAT Network 192.168.136.0/24

    I was testing the IPSec Connections on PfSense, but did I realy setup one Phase2 for every local Subnet for NAT?

    On OpenBSD we have a loopback Interface for NAT.

    "localnetwork>NAT_loopback_Interface>Tunnel>remote Network"
    "192.168.x.x>192.168.136.1>ESP>10.200.0.0/16"

    But did not find any Option for creating loopback Interface on PFsense.

    Or is there a easy way for NAT from multiple local Subnet into IPSec Tunnels?

    I don`t want to have like over 100 Phase2 Tunnels.

    Thanks a lot.



  • You can specify the NAT translation on the phase2 settings page.
    It is clearly marked as NAT segment translate.


Log in to reply