TNSR IPsec Hub for pfSense Software Nodes

This recipe covers the following scenario:

Headquarters (HQ) is a hub with 3 branch sites as spokes. This recipe creates a secure interconnection between the local networks at all sites. This recipe assumes one of the branch routers is capable of using BGP for routing. One branch also requires the ability to route its Internet traffic through the hub node.

Tip

This recipe does not contain configuration examples for IPsec cryptographic acceleration, which can greatly improve the efficiency and performance of IPsec tunnels. The availability of acceleration varies by hardware, so the specifics of acceleration configuration must be customized to the target environment.

For more information, see IPsec Cryptographic Acceleration