• Ikev2 eap-mschapv2 on multiple interfaces? Possible?

    2
    0 Votes
    2 Posts
    673 Views
    F
    Hello, Thread necromancer here with the same question. I have successfully followed this guide: https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/configuring-an-ipsec-remote-access-mobile-vpn-using-ikev2-with-eap-mschapv2.html#Create_Client_Pre-Shared_Keys, and have had an IKEv2 P1 setup for years. I have a segmented network and allowing LAN access to loop back to the WAN interface was creating odd exceptions that allow a LAN user to have access to services that would be blocked by normal WAN rules, so I explicitly block LAN to WAN_address from a floating rule. I now want to allow IKEv2 from LAN into secure segments but I can only bind my P1 to one interface. No worries. I got to setup a second P1 on accessible interface and run into the same thing as the OP. I presented with a 'remote gateway address' option and no EAP options. It's as if pfSense is presuming any additional P1 are always going to be a client as a oppose to the already created server. I may be thinking about this wrong, any help appreciated.
  • Masquerade two different local nets into IPSEC tunnel [solved]

    4
    0 Votes
    4 Posts
    625 Views
    iorxI
    Hi, almost cross posting here . Because this need some visibility so other don't have to waste hours finding out that Cisco may needs this option with multiple phase 2 for a stable connection. Ref: https://forum.netgate.com/topic/132546/ipsec-phase2-problem-pfsense-checkpoint a slight hijack of this thread from me. Split Connection was the solution to my problems too. IKE2, multiple phase 2 and Cisco ASA don't play well together (single phase 2 had no problems). This particular connection has now bean stable, 14h and counting. Brgs,
  • IPSec phase2 problem - pfSense - Checkpoint

    10
    0 Votes
    10 Posts
    2k Views
    iorxI
    Hi ladies and germs. Split Connection was the solution to my problems. IKE2, multiple phase 2 and Cisco ASA don't play well together (single phase 2 had no problems). Split Connection is what got my connection stable, 14h and counting now. A link from the pfsense UI to the docs or a hint in the description on the option that Cisco probably needs this when running multiple phase 2 had been very helpful and saved me a couple of hours. Brgs,
  • Active Phase 2s do not match traffic flowing across tunnel

    1
    0 Votes
    1 Posts
    205 Views
    No one has replied
  • duplicate tunnels

    10
    0 Votes
    10 Posts
    523 Views
    B
    I'm going to have to google some of the things you talked about. I set reauth = no and rekey = no. Its been about 2 days and do far so good no reboots needed and no duplicate tunnels creeping up.
  • pfSense to Sonicwall with failover on Sonicwall

    3
    0 Votes
    3 Posts
    389 Views
    U
    @Perforado thanks for the reply! The dual gateway is on the Sonicwall, not the pfSense. What I am wondering is how to best leverage Sonicwall failover to a site pfSense IP.
  • ipsec1000 down

    2
    0 Votes
    2 Posts
    198 Views
    D
    Solved.
  • How to setup multiple concurrent L2TP users?

    l2tp vpn ipsec
    2
    0 Votes
    2 Posts
    412 Views
    M
    I could not find my previous post, I thought it was not posted properly, now I found it but can not remove this one... please Admin, remove it and pardon my mistake
  • 0 Votes
    1 Posts
    402 Views
    No one has replied
  • IKEv2 Certificate + EAP (Username/Password) and freeradius

    4
    0 Votes
    4 Posts
    838 Views
    jimpJ
    Correct. You can choose from either EAP-TLS which has certificates in both directions (client and server) or EAP-MSCHAPv2/EAP-RADIUS which has user auth + clients validate server certificate. There isn't a way for both to work currently. (And even if strongSwan supported it, I'm not sure any clients do)
  • Multiple Concurrent VPN connection L2TP/IPsec

    ipsec l2tp vpn
    1
    0 Votes
    1 Posts
    440 Views
    No one has replied
  • Strange Problem With Copying Files on IPSec

    1
    0 Votes
    1 Posts
    221 Views
    No one has replied
  • 1 Votes
    6 Posts
    1k Views
    kiokomanK
    no idea sorry, as jimp mentioned 0.0.0.0 is used for other stuff inside pfsense, you need to wait for the dev to find a better solution or use dyndns
  • Odd One way IPSec Communication issue

    10
    1 Votes
    10 Posts
    2k Views
    T
    @jimp Yup, i was just typing up a response saying I found that while reviewing my post. It's always the little things. thanks for guiding me through the troubleshooting steps! edit: It also was set to "LAN Address" instead of "LAN Net"
  • 0 Votes
    5 Posts
    564 Views
    P
    @jimp said in IPSEC VTI Interface neighbor MTU 1500 is larger then ipsec2000´s MTU 1400: affe8a552ef1f7b8e59f3b60fd1421aa46f45b03 Done. Thank you.
  • Voice Traffic Over IPSEC Tunnel

    1
    0 Votes
    1 Posts
    156 Views
    No one has replied
  • IPSec/L2TP listen address 0.0.0.0 on reboot

    8
    0 Votes
    8 Posts
    793 Views
    R
    Was able to get internal clients connecting just by adding a host override for my vpn domain name to point to pfsense e.g. 192.168.1.1 instead of trying to come in via the WAN IP Not sure what I achieved in the end, but happy days..
  • 0 Votes
    9 Posts
    881 Views
    jimpJ
    No wonder it's broken. Every tunnel should be using a unique set of identifiers. Otherwise nothing can be distinguished from each other.
  • Route one site over IPsec

    4
    0 Votes
    4 Posts
    510 Views
    awebsterA
    @unsichtbarre No, I don't think you can create a phase 2 VTI and a legacy phase 2 under the same phase 1. You would need to create a new VTI based IPSEC tunnel between sites A and B and use that exclusively. Although it might be possible to run parallel IPSEC tunnels if the endpoint IP is different at one end or the other.
  • Route all traffic through IPSec

    2
    0 Votes
    2 Posts
    303 Views
    B
    I figured it out! Because of the way that my gateways are configured, I had to set up a firewall rule for Site B's subnet on Site A's router under IPSec that has a gateway that is the same as my outbound NAT.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.