Skip to Main Content

Cloud Platform

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

Setting up IPSEC using pfsense VM (virtual box) to OCI on a desktop

kftron1Jan 23 2022

Here is my setup:
Host O/S - Ubuntu (20.4), Virtualbox (6.1 -running pfsense o/s 2.4). Standard ISP connection (AT&T pace router).
Public IP End point is known for local LAN (DHCP assigned IPs by ISP).
Subnet for the virtual and physical host are common and pingable.
ISP router set for routing to ISP endpoint to VM pfsense.

ON OCI:
All infra setup. but a few questions:
1> for Tunneling, for the destination IP CIDR, do I use the local lan subnet or the ISP's public subnet here? I assume a /24 CIDR . If it is the public (ISP) endpoint, then the router is set to go to the IP of the pfsense first (no DHCP is setup on pfsense b/c it is on the same subnet as the local lan after the public endpoint terminates to my local lan. If it is the ip of the local lan, I can't see how this could be routed given nothing is known from the 'outside' of my local subnet.
2> On OCI, There is a optional IPV4 tunnel within the IPsec tunnel possible. Is this for routing traffic from public endpoint (ISP assigned IP to my local router) to a lan constructed using pfsense where it could serve as a DHCP server within a 'private' network?
I have been working on this for sometime and would appreciate any help. It seems most of the documentation vis MOS and even on the internet is geared to on-prem envs so endpoint negotiation/translation to local on-prem networks is assumed to be worked out. In my case, I have a desktop with a connection to OCI via an ISP provider. The jump between public ip and local lan is a little unclear. I have configured the router to make the pipe connected but an clarification on this re: this network plumbing would be very helpful. Any doc you can send my way would be greatly appreciated.

Comments
Post Details
Added on Jan 23 2022
0 comments
254 views