Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
21.7 Legacy Series
»
Traffic ist routed trough IPSecVPN from Sources other than defined in Phase2.
« previous
next »
Print
Pages: [
1
]
Author
Topic: Traffic ist routed trough IPSecVPN from Sources other than defined in Phase2. (Read 3397 times)
Barney Calhoun
Newbie
Posts: 2
Karma: 0
Traffic ist routed trough IPSecVPN from Sources other than defined in Phase2.
«
on:
July 27, 2021, 05:33:02 pm »
Hello List,
thanks to get your attention...I'm managing a OPNsense (v21.1.6) with two external and about 5 internal interfaces let's call them Zones. One internal Zone, connected to a physical internal interface should communicate to Segment: 1.2.3.0/24 (for Example) through the second external interface which works fine, and an other internal Zone which is connected to a VLAN-Interface should communicate, unfortunately, to the identical IP-Range (1.2.3.0/24) through an IPSec-VPN.
So to be clear:
192.168.1.0/24 on Int1 through Ext2 to 1.2.3.0/24
and
192.168.2.0/24 on VLAN2 through an IPSecVPN to 1.2.3.0/24
The destinations (1.2.3.0/24) are different serviceproviders for different purposes.
So i've configured phase2 of the IPSecVPN with the obove source net (192.168.2.0/24) and destination.
First it all worked fine, which was clear to me, because i configured the source (192.168.2.0/24) in phase2, so the IPSecVPN should not be used for source 192.168.1.0/24...but a couple of days later i realized that it did that, the traffic comming from 192.168.1.0/24 was routed through the IPSecVPN to the wrong Serviceprovider.
Maybe this scenario is unsupported, are there any hints what to do in such a case (identical target IP-Ranges with diferent providers)?
any help is welcome...
Logged
Patrick M. Hausen
Hero Member
Posts: 6721
Karma: 566
Re: Traffic ist routed trough IPSecVPN from Sources other than defined in Phase2.
«
Reply #1 on:
July 27, 2021, 05:39:59 pm »
You could try to create a route based VPN and force a gateway through firewall rules. But with policy based you are stuck - the kernel will encapsulate everything that matches your phase 2 SA and send it to the peer.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
21.7 Legacy Series
»
Traffic ist routed trough IPSecVPN from Sources other than defined in Phase2.