This article will help you connect and secure your pfSense installation with Acreto Ecosystem.
Firstly, you will need to create a new Gateway device in the Acreto platform. Instructions on how to create a new Gateway are available here.
To simplify testing, add the IP addresses of all interfaces connected to your gateway as Local Networks (you can use /32 prefix for public interface). This will allow you to test connectivity from the gateway through Acreto by using Ping, Traceroute, or similar tools.
To proceed with the pfSense configuration, you will need a few values from an existing committed Acreto Gateway:
All of these may be found within the Gateway details panel - view the below animation for further instruction.
Log in to your pfSense panel.
Go to VPN > IPsec. Click on Add P1 to configure the Phase 1 settings.
In the following window, configure VPN Phase1 settings as below:
Click Save to save the configuration.
Click on Show Phase 2 Entries and Click on Add P2.
In the next window, configure the Phase 2 setting as below:
Click on Save.
Click on Apply Changes to save the configuration.
Go to Firewall > Rules and select LAN
Click on Add button to add a new rule.
In the next window, configure policy as below:
Go to Firewall > NAT.
Select Outbound, and in the Mapping section click on the Add button.
In the next window, configure the rule as below:
Click on Save
Click on Apply Changes to save the NAT rule.
In the same window, select mode Hybrid Outbound NAT rule generation. (Automatic Outbound NAT + rules below) in Outbound NAT Mode.
Click on Apply Changes to save settings.
Go to Status > IPsec.
The following window will show the status of the VPN as below. Click on Connect VPN if the tunnel is down.
Go to Diagnostics » Ping.
In the next windows, check ping as below:
Ping should be successful, and logs on the Wedge dashboard should show the same record.
Go to VPN > IPsec and click on Advanced Setting.
In IPsec bypass rules, enter the source and destinations of your local traffic, which doesn’t need to go through Acreto VPN.
Once the VPN connection is successfully established, all the internet traffic will be routed through the Acreto.