OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Profile of Colani1200 »
  • Show Posts »
  • Messages
  • Profile Info
    • Summary
    • Show Stats
    • Show Posts...
      • Messages
      • Topics
      • Attachments

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

  • Messages
  • Topics
  • Attachments

Messages - Colani1200

Pages: 1 [2]
16
Virtual private networks / Can't get NAT before IPsec to work
« on: April 12, 2021, 03:00:15 pm »
Hi all,

I have to migrate a VPN tunnel from another gateway to OPNsense which relies on NAT before IPsec. The tunnel looks like this:


    LAN                                                                                              Customer site
---------------         NAT             -----------------------      IPsec            -----------------
|Network A  |  -----------------> |IP from Network B| -----------------> |  Network C  |
---------------                           -----------------------                          -----------------

This is a pretty common scenario in corporate environments. From what I've read, there were problems doing this with OPNsense in the past, but it should be possible with the current version 21.1.4 which I'm running.

In phase2, I have defined B as local network and C as remote network and I added network A as a manual SPD entry. The tunnel comes up fine, but my outbound NAT rule refuses to work when I bind it to the IPsec interface. When I bind the very same NAT rule to the WAN interface, traffic gets NATed as expected, but apparently it does not enter the tunnel.

Any idea what I am missing?

17
German - Deutsch / Re: IPSec - Natten der IP Adresse
« on: April 08, 2021, 11:11:45 am »
Sorry wenn ich hier einen alten Thread kapere, aber ich habe aktuell dasselbe Problem wie der OP und komme nicht so recht weiter. Das Problem ist, dass meine NAT-Regel partout nicht greifen will. Ich habe schon probiert die NAT-IP auf das WAN-Interface zu binden, aber das hat auch nicht geholfen. Was aus den bisherigen Posts nicht ganz eindeutig hervorgeht: Funktioniert das jetzt nur mit Route-based IPsec? Muss ich Tunables setzen?

Pages: 1 [2]
OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2