Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN Multiple Site-to-Site

    Scheduled Pinned Locked Moved OpenVPN
    9 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      gst.freitas
      last edited by

      OpenVPN Multiple Site-to-Site

      I wonder if paa each site connection I have to create one on the server.

      Site A - port 1194 - Site B
      Site A - port 1195 - Site C

      or can I use the same connection in 1194 the B port to C?

      I am using peer to peer (shared key)

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        You can set up one server on A and connect B anc C to it.  You can route traffic from B to C through A.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • G
          gst.freitas
          last edited by

          In need true that all you be centered on A, 'cause will be B, C, D ..G.. have to create for each connection?

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            You can do as many in the "star" as you like, capabilities of the circuits and hardware being taken into consideration, of course.

            You have to create a client for each connection, yes.  They can all connect to the same server.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • G
              gst.freitas
              last edited by

              I think I was not clear .. have to create multiple connections to the server? for each connection have qu have an OpenVPN server on different ports?

              example, or only one server can have site B, C, D

              openvpn.jpg
              openvpn.jpg_thumb

              1 Reply Last reply Reply Quote 0
              • J
                jdp0418
                last edited by

                I am not sure what you mean by multiple connections to the server.  Do you mean port forwards/firewall openings?  Your server just needs to be listening on whatever TCP/UDP port you setup for the server.  Just make sure you are allowing traffic in on those ports on the WAN of your firewall.

                As stated, you can have one server with multiple clients.  All clients should point back to the same hostname/IP and port (1195 or 1196 in your config).

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  only one server can have site B, C, D

                  Yes.  (Actually, you can do it either way)

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • G
                    gst.freitas
                    last edited by

                    sorry,

                    I could explain I can do using just an OpenVPN server on a single port? because I tested here and it did not work

                    1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate
                      last edited by

                      Just set up different clients.  They will all get a /30 out of your tunnel network.

                      Sorry, but I am not going to rehash all the OpenVPN documentation again here.  doc.pfsense.org.

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.