<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[NAT IPsec Lan to lan issue]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I’m working in a case with I am using a VPN IPsec between two sites<br />
Site 1</p>
<ul>
<li>Public IP : 195.1.1.1</li>
<li>VPN LAN IP 1 : 10.28.x.0/24</li>
<li>VPN LAN IP 2 : 10.28.y.0/21</li>
</ul>
<p dir="auto">Site 2</p>
<ul>
<li>
<p dir="auto">Public IP: 51.2.2.2</p>
</li>
<li>
<p dir="auto">Pfsense Virtual Network : 10.29.183.192/26<br />
        o Internal IP : 172.16.0.14<br />
        o Virtual IP 1 : 10.29.183.193<br />
        o Virtual IP 2 : 10.29.183.194</p>
</li>
<li>
<p dir="auto">LAN IP : 172.16.0.0/16<br />
        o Server 1 : 172.16.0.8</p>
</li>
<li>
<p dir="auto">The  VPN corrects correctly</p>
</li>
<li>
<p dir="auto">The server 1 (172.16.0.8 ) and the server 2 (172.16.0.11) can ping the Pfsense Virtual Network : 10.29.183.192/26 I have added the route</p>
</li>
<li>
<p dir="auto">When I’m connect on the Pfsense console (Site 2), I can ping<br />
        o the VPN LAN on the site 1<br />
        o the 172.16.0.0 on the site 2</p>
</li>
<li>
<p dir="auto">On the server I have rewritten the routes :</p>
</li>
<li>
<p dir="auto">Persistent Routes:<br />
  Network Address          Netmask  Gateway Address  Metric<br />
      10.28.x.0    255.255.255.0      172.16.0.14      1<br />
      10.28.y.0    255.255.248.0      172.16.0.14      1<br />
          0.0.0.0          0.0.0.0        x.x.x.x   Default<br />
    10.29.183.192  255.255.255.192    172.16.0.14      1</p>
</li>
</ul>
<p dir="auto">The NAT 1:1 is enable</p>
<p dir="auto">But the server 1 (172.16.0.8 | site 2) can’t ping a server in the site 1.<br />
Have you any idea ?</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/nat.png" alt="nat.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/nat.png_thumb" alt="nat.png_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/92128/nat-ipsec-lan-to-lan-issue</link><generator>RSS for Node</generator><lastBuildDate>Thu, 14 May 2026 10:18:06 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/92128.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 24 Nov 2015 11:24:53 GMT</pubDate><ttl>60</ttl></channel></rss>