Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSec and bridging

    Scheduled Pinned Locked Moved IPsec
    4 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      shpokas
      last edited by

      Hi guys,
      is there a way to configure IPSec so that VPN clients are part of a bridged network?
      I have done that with OpenVPN a couple of times and people appreciate that. And SoftEther also seems to be able to do just that.

      Because IPSec clients always have IP addresses from a different network, it does nt seem possible, correct?
      Maybe this is complete nonsense, but perhaps it can be mitigated by overlapping server LAN IP adresses with client assigned segment?
      Server LAN 10.1.0.0/8
      Client LAN 10.100.0.0/8

      I would imagine that TCPIP datagrams would then be broadcasted - but really would they?
      Thanks, shpokas

      10-4-1.png
      10-4-1.png_thumb

      1 Reply Last reply Reply Quote 0
      • K
        kapara
        last edited by

        Why is it an issue to have IP addresses on different subsets?

        Skype ID:  Marinhd

        1 Reply Last reply Reply Quote 0
        • S
          shpokas
          last edited by

          When VPN client is in the same network as servers, network resources are visible in file tools - Windows Explorer or Finder.
          Makes a difference for many.

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            What you actually want is the client on the same broadcast domain, not (just) the same IP subnet. You can use a mobile IPsec tunnel network that's a subset of your LAN, if you add proxy ARP on LAN for that subset, but that won't get the clients on the same broadcast domain. No mobile IPsec clients support that.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.