<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenVPN to IPSec?]]></title><description><![CDATA[<p dir="auto">I'd like to convert my OpenVPN site-to-site links to IPSec to take advantage of the higher speeds offered by IPSec. However, I am extremely confused about how to replicate my current OpenVPN setup/routing.</p>
<p dir="auto">For OpenVPN - Site A (client) connects to Site B (server) and in the settings on each side I have the local and remote subnets listed. I allow all on the correct firewall tabs and pfSense takes care of routing everything. The pfSense boxes can hit each other and clients behind each pfSense can ping clients behind the other pfSense.</p>
<p dir="auto">If I want to convert this to IPsec, I should create a Phase 1 entry at each side. I can do this and I see the Phase 1 entry connect. I then create a Phase 2 entry for one of my multiple subnets … and this is where I am stuck. I cannot get any traffic to pass and the two pfSense boxes cannot even ping each other.</p>
<p dir="auto">What am I missing here? I can't do much experimentation because this is a production link between our datacenters.</p>
]]></description><link>https://forum.netgate.com/topic/99003/openvpn-to-ipsec</link><generator>RSS for Node</generator><lastBuildDate>Sun, 12 Jul 2026 18:05:48 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/99003.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 26 Apr 2016 19:02:38 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to OpenVPN to IPSec? on Sun, 22 May 2016 14:29:48 GMT]]></title><description><![CDATA[<p dir="auto">I finally got around to this and it's working great. Thank you.</p>
<p dir="auto">If I wanted to route all internet traffic through the site-to-site VPN, is this article still valid?</p>
<p dir="auto">https://doc.pfsense.org/index.php/Routing_internet_traffic_through_a_site-to-site_IPsec_tunnel#Configure_outbound_NAT</p>
<p dir="auto">At the end, it says to modify the Outbound NAT at <strong>Site B</strong> (where you want your Internet traffic to exit), even though you want <strong>Site A</strong> to use the <strong>Internet at Site B</strong>. Is that still correct?</p>
<p dir="auto">Edit: This worked perfectly, I missed where it said to add a route of 0.0.0.0/0 at Site A, thus my confusion.</p>
]]></description><link>https://forum.netgate.com/post/626429</link><guid isPermaLink="true">https://forum.netgate.com/post/626429</guid><dc:creator><![CDATA[mevans336]]></dc:creator><pubDate>Sun, 22 May 2016 14:29:48 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN to IPSec? on Tue, 26 Apr 2016 21:00:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dotdash">@<bdi>dotdash</bdi></a>:</p>
<blockquote>
<p dir="auto">IPsec just needs the p2 to match the subnets. You can have multiple phase2's. In addition, you need to allow the traffic on the IPSec tab of the firewall rules. Try an any any to get it going and narrow it down later.</p>
</blockquote>
<p dir="auto">Ok, so I need a single P1 - then just a P2 for each subnet I want routed from site-to-site? I will delete the OpenVPN site-to-site and give this another shot tonight. Thank you.</p>
]]></description><link>https://forum.netgate.com/post/619990</link><guid isPermaLink="true">https://forum.netgate.com/post/619990</guid><dc:creator><![CDATA[mevans336]]></dc:creator><pubDate>Tue, 26 Apr 2016 21:00:49 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN to IPSec? on Tue, 26 Apr 2016 20:02:18 GMT]]></title><description><![CDATA[<p dir="auto">IPsec just needs the p2 to match the subnets. You can have multiple phase2's. In addition, you need to allow the traffic on the IPSec tab of the firewall rules. Try an any any to get it going and narrow it down later.</p>
]]></description><link>https://forum.netgate.com/post/619976</link><guid isPermaLink="true">https://forum.netgate.com/post/619976</guid><dc:creator><![CDATA[dotdash]]></dc:creator><pubDate>Tue, 26 Apr 2016 20:02:18 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN to IPSec? on Tue, 26 Apr 2016 19:24:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dotdash">@<bdi>dotdash</bdi></a>:</p>
<blockquote>
<p dir="auto">Edit- I suppose it could be faster if you had AES-NI hardware and very fast links…</p>
</blockquote>
<p dir="auto">Which I do. Haswell Xeon CPUs and 1Gbps between sites.</p>
<p dir="auto">It's the same reason I run IPSec via PIA at home. I can hit 600-700Mbps over PIA with IPSec, but only a few hundred Mbps with PIA over OpenVPN.</p>
]]></description><link>https://forum.netgate.com/post/619961</link><guid isPermaLink="true">https://forum.netgate.com/post/619961</guid><dc:creator><![CDATA[mevans336]]></dc:creator><pubDate>Tue, 26 Apr 2016 19:24:16 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN to IPSec? on Tue, 26 Apr 2016 19:19:22 GMT]]></title><description><![CDATA[<p dir="auto">Where did you hear IPSec would give you superior speed? Citation needed. Most people are converting things the other way.<br />
Edit- I suppose it could be faster if you had AES-NI hardware and very fast links…</p>
]]></description><link>https://forum.netgate.com/post/619958</link><guid isPermaLink="true">https://forum.netgate.com/post/619958</guid><dc:creator><![CDATA[dotdash]]></dc:creator><pubDate>Tue, 26 Apr 2016 19:19:22 GMT</pubDate></item></channel></rss>