Using IPsec with Multiple Subnets

On current versions of pfSense® software, additional subnets are handled by adding an additional Phase 2 entry to cover the path to pass through the tunnel.

For example, for and at Site A, and at Site B, define two Phase 2 entries on both sides:

On the Site A Firewall: to to

On the Site B Firewall: to to

This works for any additional networks on either side (VPN subnets, networks on the other end of VPNs connected to the remote router, etc).

If the equipment to which the tunnel connects does not support multiple Phase 2’s, it may be necessary to employ supernetting/CIDR summarization (See below) to fit the networks into a single Phase 2.

Supernetting Example

At Site A, there is one subnet, This should reach,, and at Site B.

Due to the “closeness” of the subnets, they could be grouped into a larger network in the tunnel definition: (This would also include