OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Access Remote Subnet over IPSec Tunnel
« previous next »
  • Print
Pages: [1]

Author Topic: Access Remote Subnet over IPSec Tunnel  (Read 3556 times)

tuaris

  • Jr. Member
  • **
  • Posts: 61
  • Karma: 4
    • View Profile
    • Unibia.net
Access Remote Subnet over IPSec Tunnel
« on: July 30, 2017, 08:55:18 pm »
I have two location each with 2 sub-nets. One location uses a OPNSense router, the other a m0n0wall (that will soon be updated to OPNSense).

The m0n0wall is connected to the sub-nets:

192.168.7.0/24
10.9.9.0/24

The OPNSense is connected to:

192.168.0.0/24
10.8.8.0/24

There are two IPSec tunnels.  One connects 192.168.0.0/24 and 192.168.7.0/24 and the second connects 10.8.8.0/24 and 10.9.9.0/24.



My problem is that I am unable to figure out how to allow hosts on 192.168.0.0/24 to reach hosts on 10.9.9.0/24, and vice versa.  Can anyone give my a hint?
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17701
  • Karma: 1615
    • View Profile
Re: Access Remote Subnet over IPSec Tunnel
« Reply #1 on: July 31, 2017, 08:45:29 am »
Hi tuaris,

Is this IKEv1? Under IKEv2 with one Phase 1 and two Phase 2 this shouldn't be an issue as the subnets are being meshed:

rightsubnet = 10.8.8.0/24,10.9.9.0/24


Cheers,
Franco
Logged

BertM

  • Jr. Member
  • **
  • Posts: 53
  • Karma: 12
    • View Profile
Re: Access Remote Subnet over IPSec Tunnel
« Reply #2 on: October 31, 2017, 11:47:59 am »
tuaris,

You need to add a phase2 entry for all traffic that need to pass to the other side.
You already made two phase2 entries, one connecting 192.168.7.0/24 to 192.168.0.0/24, and one connecting 10.9.9.0/24 to 10.8.8.0/24.
You just need to add a third phase2 entry connecting 192.168.0.0/24 to 10.9.9.0/24

Kind regards,
Bert
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Access Remote Subnet over IPSec Tunnel
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2