Configurando VPN entre EdgeOS e OpnSense/PFSense


Acesse por SSH e adicione as regras ajustando de acordo:

set interfaces openvpn vtun0 description teste-site-2-site
set interfaces openvpn vtun0 encryption aes256
set interfaces openvpn vtun0 hash sha256
set interfaces openvpn vtun0 local-address 10.8.8.2
set interfaces openvpn vtun0 local-port 1194
set interfaces openvpn vtun0 mode site-to-site
set interfaces openvpn vtun0 openvpn-option '--ping 10'
set interfaces openvpn vtun0 openvpn-option '--ping-restart 20'
set interfaces openvpn vtun0 openvpn-option '--user nobody'
set interfaces openvpn vtun0 openvpn-option '--group nogroup'
set interfaces openvpn vtun0 openvpn-option '--verb 5'
set interfaces openvpn vtun0 openvpn-option 'mssfix 1450'
set interfaces openvpn vtun0 openvpn-option 'tun-mtu 1500'
set interfaces openvpn vtun0 openvpn-option --comp-lzo
set interfaces openvpn vtun0 openvpn-option --float
set interfaces openvpn vtun0 openvpn-option --ping-timer-rem
set interfaces openvpn vtun0 openvpn-option --persist-tun
set interfaces openvpn vtun0 protocol udp
set interfaces openvpn vtun0 remote-address 10.8.8.1
set interfaces openvpn vtun0 remote-host 200.200.100.255
set interfaces openvpn vtun0 remote-port 1194
set interfaces openvpn vtun0 shared-secret-key-file /config/auth/secret

Adicione a rota para os destinos desejáveis

set protocols static interface-route 192.168.1.0/24 next-hop-interface vtun0

Você achou esse artigo útil?