<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[[Solved] Howto route local traffic between diff. Subnets AND IPSEC supernetting]]></title><description><![CDATA[<p dir="auto">Here's my setup:</p>
<p dir="auto">Site 1, pfsense 2.2.2<br />
LAN A =&gt; 192.168.0.1/24<br />
LAN B =&gt; 192.168.1.1/24</p>
<p dir="auto">Site 2, pfsense 2.2.2<br />
LAN =&gt; 192.168.100.1/24</p>
<p dir="auto">Mission:<br />
Route all traffic from Site1 thru Site2<br />
but still allow routing locally from LAN A to LAN B.</p>
<p dir="auto">Setup:<br />
IPSEC Phase 1 connects to Site 2 (sucessfull)<br />
IPSEC Phase 2: LAN A to 0.0.0.0/0 (sucessfull)<br />
IPSEC Phase 2: LAN B to 0.0.0.0/0 (sucessfull)</p>
<p dir="auto">The tunnel comes up and traffic is passing thru.</p>
<p dir="auto">Unfortunalty, LAN A now can't reach LAN B locally anymore.</p>
<p dir="auto">What do I have to do to make LAN B locally available for LAN A.</p>
<p dir="auto">cu<br />
Ben</p>
]]></description><link>https://forum.netgate.com/topic/83351/solved-howto-route-local-traffic-between-diff-subnets-and-ipsec-supernetting</link><generator>RSS for Node</generator><lastBuildDate>Tue, 21 Jul 2026 01:38:28 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/83351.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 26 Apr 2015 00:29:31 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to [Solved] Howto route local traffic between diff. Subnets AND IPSEC supernetting on Sun, 03 May 2015 01:07:06 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for your answers.</p>
<p dir="auto">Here's how I've solved the problem:<br />
I set up my ipsec connection and "phased around" all my LAN Subnets in Phase 2. To route around, I just needed a couple of phase 2 entries.</p>
<p dir="auto">0.0.0.0/1<br />
128.0.0.0/2<br />
192.0.0.0/9<br />
192.128.0.0/11<br />
192.160.0.0/13<br />
…</p>
<p dir="auto">cu<br />
Ben</p>
]]></description><link>https://forum.netgate.com/post/541562</link><guid isPermaLink="true">https://forum.netgate.com/post/541562</guid><dc:creator><![CDATA[pfsenseman081]]></dc:creator><pubDate>Sun, 03 May 2015 01:07:06 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] Howto route local traffic between diff. Subnets AND IPSEC supernetting on Fri, 01 May 2015 00:26:03 GMT]]></title><description><![CDATA[<p dir="auto">There isn't a way to accommodate that in the GUI currently. The "conn bypasslan" entry in ipsec.conf, generated by /etc/inc/vpn.inc, adds a passthrough but only for the LAN's subnet. That could be easily changed to hard code your LAN subnets in vpn.inc as a work around. There is a feature request open to add that functionality in the future.</p>
]]></description><link>https://forum.netgate.com/post/541220</link><guid isPermaLink="true">https://forum.netgate.com/post/541220</guid><dc:creator><![CDATA[cmb]]></dc:creator><pubDate>Fri, 01 May 2015 00:26:03 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] Howto route local traffic between diff. Subnets AND IPSEC supernetting on Sun, 26 Apr 2015 00:55:19 GMT]]></title><description><![CDATA[<p dir="auto">How about using a layer 3 switch and have the switch be the primary gateway and do inter-vlan routing between both subnets at the switch and have all other traffic go to the pfsense.  another option is to throw a router in between your pfsense and your switch and have that be the gateway.</p>
<p dir="auto">That way pfsense does not have to handle the routing of the 2 subnets and your ipsec routing should not interfere.</p>
<p dir="auto">You can either go opensource with a switch or router or go with Cisco SMB Switch</p>
<p dir="auto"><a href="http://www.cisco.com/c/en/us/products/switches/small-business-300-series-managed-switches/models-comparison.html" target="_blank" rel="noopener noreferrer nofollow ugc">http://www.cisco.com/c/en/us/products/switches/small-business-300-series-managed-switches/models-comparison.html</a></p>
]]></description><link>https://forum.netgate.com/post/539842</link><guid isPermaLink="true">https://forum.netgate.com/post/539842</guid><dc:creator><![CDATA[kapara]]></dc:creator><pubDate>Sun, 26 Apr 2015 00:55:19 GMT</pubDate></item></channel></rss>