Routing my lan network to PFSense VPN - HELP

bikkembergz
Comes here often

Routing my lan network to PFSense VPN - HELP

I'm using PFsense as site-to-site VPN to external site.

 

my network is 192.168.21.0/24

pfsense ip: 192.168.21.2 (tunnel vpn ip: 10.8.0.0/24)

External network 10.132.0.0/20 (I can ping this network from pfsense while VPN is active )

 

I need to route all 192.168.21.0/24 traffic to 10.132.0.0/20 network.


Is the "static route" the best way?

Static route input form asking: Name; Subnet; Next hop ip.

How can I setup Meraki MX to add my route?

5 Replies 5
KarstenI
Kind of a big deal
Kind of a big deal

Yes, you need static routes to the remote network pointing to the PFsense IP. And the PFsense firewall needs a route for your internal network to the MX IP.

bikkembergz
Comes here often

Thanks for your reply.
Could you better explain the second point? 

Why PFsense firewall needs a rout to MX IP? To allow "bi-directional access"? 

 

Is need to allow Google Network access to my local network?

KarstenI
Kind of a big deal
Kind of a big deal

I just see that your PFsense device is part of your internal network. This can give you asymmetric routing to/from your external network. Better put the PFSense box in a dedicated DMZ and configure the routing as mentioned.

bikkembergz
Comes here often

Thanks!

Last questions:

Adding route to external networks from LAN everything is working fine.

 

Last problem: this route is not working from client-vpn. 

I tried to connect to office lan from home and the static route doesn't works.

How can I add this route also to client vpn network? (192.168.99.x)

KarstenI
Kind of a big deal
Kind of a big deal

For the Network 192.168.99.0/24 you need

  • to add this network to your s2s VPN
  • a route pointing to the s2s-tunnel on the remote network
  • a route pointing to the local MX on the PFsense gateway
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels