Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Mesh VPN with OpenVPN

    Scheduled Pinned Locked Moved OpenVPN
    3 Posts 2 Posters 4.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      TC10284
      last edited by

      So I currently have three sites that I need setup with some type of mesh VPN. Hub and spoke is an option, but it is not preferred.

      Site1 - 192.168.16.0/24 (primary site with our server)
      Site2 - 192.168.1.0/24
      Site3 - 192.168.2.0/24

      Each site has a pfSense box in place. Site1 and Site2 are currently connected properly with OpenVPN
      Each time I try to connect Site3 to Site1, Site3 gets the tunnel IP of Site2, which is 10.10.10.1

      In the near future, we will need a fourth site setup and connected to our network.

      What is the best way to setup a "mesh" VPN? It does not even have to use OpenVPN as long as it is fairly simple enough to setup.
      I would prefer OpenVPN, but would need help on what to do.

      Thanks!

      1 Reply Last reply Reply Quote 0
      • T
        TC10284
        last edited by

        So after many hours of trial and failure, I came across these two guides and thus far it has got me working with IPsec across all three sites so far.
        I have yet to do a full mesh setup with IPsec thus far, but I can ping the central server, which was my primary goal that I could not do previously with Site2 and Site3 simultaneously connected.

        https://www.youtube.com/watch?v=PZjf2s53sss
        http://conheotiensinh.blogspot.com/2009/11/vpn-ip-sec-site-to-site-with-pfsense.html

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          What was set as the tunnel network in the OpenVPN server and the clients?  This stuff kinda just works.

          Are you sure you need mesh?  Hub-spoke is a lot easier to maintain.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.