当前位置:网站首页>Pfsense configure tailscal site to site connection
Pfsense configure tailscal site to site connection
2022-07-19 10:03:00 【51CTO】
Tailscale Is a software defined mesh VPN Solution , It makes it easy to create a secure network .Tailscale The data plane is built on a secure and lightweight WireGuard The agreement above , Unlike other solutions , It can realize some powerful functions , For example, automatic key rotation 、NAT Traversal and single sign on with two factor authentication . Similar solutions include Zerotier, Both have their own advantages and disadvantages .
2022 year 7 month 15 Japan ,netgate Officially released for pfSense Of Tailscale Plug in for , Now you can pfSense Experience this powerful function on the firewall .
Here are two different places pfSense Take the firewall to establish a site to site connection as an example , Introduce Tailscale Configuration process .
The software used is pfSense plus 22.05 Chinese customized version , A firewall A The subnet of is 192.168.11.0/24, A firewall B The subnet of is 192.168.21.0/24. For the convenience of readers to distinguish , A firewall A Dark theme , A firewall B Light color theme .
A firewall A To configure
Navigate to plug-in management > Available plug-ins , find Tailscale And install . After installation , go to VPN>Tailscale, Go to the authentication tab , Access the address on the login server , Register with an account such as Google or Microsoft Tailscale. After registration , go to tailscale Control panel , In the settings bar , Find the key option , Generate a new key .
Click generate key :
Copy the generated key to the pre authentication key column :
Click save .
Go to the Settings tab , Check enable Tailscale, The listening port uses the default value , Select the authorized subnet route , In the announcement routing options , Enter the subnet used by the firewall . Here for 192.168.11.0/24.

Click save... When finished .
Then go to firewall > Rule strategy , stay Tailscale On the tab , Add a rule that allows access to any target, as shown in the following figure :
go back to Tailscale Control panel , You can see that this firewall is already in the device list . Click the more icons on the right , Disable key expiration .
Click Edit routing settings , Enable subnet routing :
thus , A firewall A Setup completed .
A firewall B To configure
Configuration process and firewall A identical , Note to generate a new pre authorization key , Enter different firewall subnets .



Disable key expiration , Configure subnet routing .
thus , The firewall configuration on both sides is completed .
test
Firewalls on both sides are mutually ping For terminal network address , Test connectivity .
At the firewall A On ,ping A firewall B Of LAN Address :

At the firewall B On ,ping A firewall A Of LAN Address :
There is no problem with the test connection .
Use iperf Ran a speed measurement (300M On 、 Downlink peer-to-peer bandwidth ):
There seems to be no surprise , ha-ha .
Tailscale High order application of , Such as remote outbound , Later on .
边栏推荐
- 【摸鱼神器】UI库秒变低代码工具——表单篇(二)子控件
- 第4章-一阶多智体系统一致性 -> 切换拓扑系统一致性【程序代码】
- 光辉使用输出
- mof定制产品|N-K2Ti4O9/g-C3N4/UiO-66三元复合材料|纸基Au-AgInSe2-ZIF-8纳米复合材料
- 【C语言】浅涉常量、变量
- Add - before the command in makefile to ignore the error caused by the command and continue to execute the next command
- 华为无线设备配置静态负载均衡
- Clwy permission management (I) -- project construction
- node+express搭建服务器环境
- 自己创建的模块 使用cmd打开报 ModuleNotFoundError: No module named 解决方案
猜你喜欢

数组模拟队列

Experiment 1: camera calibration experiment using Matlab toolbox

关于基础模块中的依赖由微服务中的子模块继承的时候依赖失效的问题

What is the product power of lantu dreamer?
[email protected]载体)|UiO-66/CoSO复合材料|ZIF-67纳米晶表面修饰六咪唑环三磷腈"/>硫化铜纳米粒/ZIF-8复合材料([email protected]载体)|UiO-66/CoSO复合材料|ZIF-67纳米晶表面修饰六咪唑环三磷腈

氨基的金属-有机骨架材料Fe-MOF,Fe-MIL-88NH2|Zr基金属-有机骨架催化剂(Pt-UiO-66)|齐岳生物

rhcsa 第二天 7.15

第4章-一阶多智体系统一致性 -> 切换拓扑系统一致性

第4章-一阶多智体系统一致性 -> 领航跟随系统一致性

Clwy permission management (I) -- project construction
随机推荐
PTA 1037 在霍格沃茨找零钱
Mysql高级篇学习总结11:定位执行慢的sql方法、分析查询语句EXPLAIN的使用
The study found that DNA nano device injection can be safely used for medical purposes
金属有机骨架材料/聚合物复合材料ZIF-8/P(TDA-co-HDA)|氧化锌[email protected](Fe)复合纳米材料
SSH connection to Huawei modelarts notebook
在线教育知识付费网站源码系统+直播+小程序,安装教程
Use of cookies and sessions in actual projects
实验1:使用Matlab工具箱进行相机标定实验
[动态规划]DP27 跳跃游戏(二)-中等
565. Array nesting / Sword finger offer II 001 Integer division
工程效能CI/CD之流水线引擎的建设实践
CLWY权限管理(三)--- 用户组模块
Chapter 4 - first order multi-agent system consistency - > switching topology system consistency [program code]
18. Shell Scripting (1)
氨基的金属-有机骨架材料Fe-MOF,Fe-MIL-88NH2|Zr基金属-有机骨架催化剂(Pt-UiO-66)|齐岳生物
Memory LDA LDA in Blas level-3 sgemm cublesgemmex cubulassgemm
数组模拟队列
6G空天地一体化网络高空平台基站下行频谱效率研究
Series operation of vector container (detailed explanation)
ES Restful操作






