IP tunnel in node or VM

Discussion in 'Proxmox VE: Networking and Firewall' started by janos, Nov 2, 2018.

  1. janos

    janos Member

    Joined:
    Aug 24, 2017
    Messages:
    121
    Likes Received:
    12
    Hello,

    I would like to connect 3 Proxmox server over internet to a central mikrotik router, to extend our internal network (in routed mode). (not for connecting to each proxmox, these are standalone proxmox servers)

    This is an easy thing with IPIP tunnel. What i don't know, where i create the tunnel? On the proxmox node itself, or create a VM and run the tunnel into that?

    If a VM, i think it have 2 interface, one for net, one for internal network with tagged traffix, what i can extract on the host itself and other vm-s etc (or create separate bridge per vlan, i dont know, but this is doesnt matter).

    What is the usual, and stable way for this? VM or node?

    Thanks!
     
  2. bobmc

    bobmc Member

    Joined:
    May 17, 2018
    Messages:
    50
    Likes Received:
    8
    I've done this by installing pfSense as a VM. This seems to be simplest and cleanest way to do it. While you could install VPN packages on the proxmox host, using pfSense as a VM to provide the IPSEC or OpenVPN links is much easier to manage as there is a very intuitive GUI and good documentation on settings things up.

    There's a good article on the NetGate website specifically about setting up pfSense under Proxmox.

    Make the pfSense LAN IP the default gateway for the proxmox host and guests and you should be good to go.
     
  3. janos

    janos Member

    Joined:
    Aug 24, 2017
    Messages:
    121
    Likes Received:
    12
    Hi,

    IPIP is not a VPN and not need any extra packages for this.

    Finally i configured it on the host level (its easy to do in network config file), because in this case when node up (and it have network) i can reach it via the tunnel.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice