<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Routing across IPSec Tunnels]]></title><description><![CDATA[<p dir="auto">I have a tunnel between pfsense box (192.168.100.0/24) and a palo alto (172.17.16.0/24). The tunnel works great between the 2 subnets, however there is an extra subnet on the palo alto side that we need to reach. I'm used to being able to add a route which describes its gateway as a specific IPSec tunnel, but the only options I have under Static Routes for this are my external interface, internal gateway, loopback. How do I tell pfsense that this third network is through the IPSec tunnel?</p>
]]></description><link>https://forum.netgate.com/topic/82767/routing-across-ipsec-tunnels</link><generator>RSS for Node</generator><lastBuildDate>Tue, 16 Jun 2026 13:02:29 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/82767.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 14 Apr 2015 05:41:05 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Routing across IPSec Tunnels on Fri, 17 Apr 2015 01:18:00 GMT]]></title><description><![CDATA[<p dir="auto">Yes, saw that. You know that the device the other end only has 1 x P2 configured? Most devices don't have the ability to setup multiple phase 2's, Cyberoam, Sophos UTM, vShield, Palo Alto, they all just allow multiple subnets within the single P2 config or as a route using the tunnel as the gateway. If you were already clear on that, I'm not sure what the answer is. As the 2 x P2 on the pfSense box has identical settings, apart from the subnet.</p>
]]></description><link>https://forum.netgate.com/post/537195</link><guid isPermaLink="true">https://forum.netgate.com/post/537195</guid><dc:creator><![CDATA[iammist]]></dc:creator><pubDate>Fri, 17 Apr 2015 01:18:00 GMT</pubDate></item><item><title><![CDATA[Reply to Routing across IPSec Tunnels on Fri, 17 Apr 2015 00:46:06 GMT]]></title><description><![CDATA[<p dir="auto">Key part: "charon: 16[IKE] received ATTRIBUTES_NOT_SUPPORTED error notify"</p>
<p dir="auto">The other end is sending back ATTRIBUTES_NOT_SUPPORTED, the question is why. If both your P2s are identically configured with the exception of the different networks, it's a config issue of some sort on the remote end.</p>
]]></description><link>https://forum.netgate.com/post/537179</link><guid isPermaLink="true">https://forum.netgate.com/post/537179</guid><dc:creator><![CDATA[cmb]]></dc:creator><pubDate>Fri, 17 Apr 2015 00:46:06 GMT</pubDate></item><item><title><![CDATA[Reply to Routing across IPSec Tunnels on Tue, 21 Apr 2015 03:54:19 GMT]]></title><description><![CDATA[<p dir="auto">I've attached the Status &gt; IPSec and VPN &gt; IPSec screenshots. Also, the logs for IPSec. We've stabilized the original tunnel now with the extra phase 2. But still unable to get the second subnet up. Thanks in advance.</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/VPN_IPSec.JPG_thumb" alt="VPN_IPSec.JPG_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/VPN_IPSec.JPG" alt="VPN_IPSec.JPG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/Status_IPSec.JPG_thumb" alt="Status_IPSec.JPG_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/Status_IPSec.JPG" alt="Status_IPSec.JPG" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/537176</link><guid isPermaLink="true">https://forum.netgate.com/post/537176</guid><dc:creator><![CDATA[iammist]]></dc:creator><pubDate>Tue, 21 Apr 2015 03:54:19 GMT</pubDate></item><item><title><![CDATA[Reply to Routing across IPSec Tunnels on Thu, 16 Apr 2015 05:19:38 GMT]]></title><description><![CDATA[<p dir="auto">That's how IPsec functions, the other side has to know about the additional subnets as well. It may not be configured in the same manner as ours, where we show that they're actually separate and allow separate configs, but there will at least be an option to include multiple local and remote subnets in the P2 config on any worthwhile IPsec device. That's functionally equivalent.</p>
]]></description><link>https://forum.netgate.com/post/536783</link><guid isPermaLink="true">https://forum.netgate.com/post/536783</guid><dc:creator><![CDATA[cmb]]></dc:creator><pubDate>Thu, 16 Apr 2015 05:19:38 GMT</pubDate></item><item><title><![CDATA[Reply to Routing across IPSec Tunnels on Wed, 15 Apr 2015 22:11:07 GMT]]></title><description><![CDATA[<p dir="auto">Hi all,</p>
<p dir="auto">I found the below article, which is the answer to my question. However, I'm not sure the device the other side allows multiple phase 2's and the Supernetting option won't work either due to the subnets being so different.</p>
<p dir="auto">https://doc.pfsense.org/index.php/IPsec_with_Multiple_Subnets</p>
<p dir="auto">Is there no other way around this?</p>
]]></description><link>https://forum.netgate.com/post/536694</link><guid isPermaLink="true">https://forum.netgate.com/post/536694</guid><dc:creator><![CDATA[iammist]]></dc:creator><pubDate>Wed, 15 Apr 2015 22:11:07 GMT</pubDate></item></channel></rss>