Networking help please?

Deimos

[H]ard|Gawd
Joined
Aug 10, 2004
Messages
1,166
I have setup a couple of pfsense boxes to handle a site 2 site VPN, I was wondering if someone could help me lock it down.

I had to put an allow all rule on the WAN interface for the public IP at each site, otherwise the VPN would not connect, I tried several variations and port combinations following the pfsense guides, however I couldn't get it working.

I'm using OpenVPN, I'm quite happy with how easy it was to setup, and the performance is very good.

Services I have over the tunnel are file sharing (I have a domain share setup and syncing through the tunnel, but I also want another file server to be accessible through the tunnel in emergency situations)
Exchange server
DNS
Active Directory

I was going to try only allowing certain services through the tunnel but there doesn't seem to be any interface for the OpenVPN tunnel (if I setup an ipsec tunnel it shows up as an interface that I can create filters on).

TIA.
 
How does you network diagram look? Are you going pfSense -> (tunnel) -> Cloud -> (tunnel) -> pfSense?
 
How does you network diagram look? Are you going pfSense -> (tunnel) -> Cloud -> (tunnel) -> pfSense?

That is how it sounds , which begs my question why filter ?! site2site like that is usually trust2trust and should not need be filtered. However if I recall correctlly you could prevent traffic from reaching the otehr side via a if application x for net remote then block.

ok so that is a simplified way of putting it but that would be the easiest way , of course this depends on you using different subnets on either side and just using routing to get traffic across.
 
Back
Top