Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN IPSec

    Scheduled Pinned Locked Moved IPsec
    4 Posts 4 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      nunzia
      last edited by

      Hello. I'm trying to set up an IPSec VPN in pfsense. The goal is to connect a pfsense (client) to another pfsense (server) configured as follows: https://docs.netgate.com/pfsense/en/latest/recipes/ipsec-mobile-ikev2-eap-mschapv2.html. So my question is: how can I set vips property from the web GUI of pfsense? @jimp

      1 Reply Last reply Reply Quote 0
      • MikeV7896M
        MikeV7896
        last edited by

        This post is deleted!
        1 Reply Last reply Reply Quote 0
        • viktor_gV viktor_g moved this topic from CE 2.6.0 Development Snapshots (Retired) on
        • LuKePicciL
          LuKePicci
          last edited by

          I was recently struggling on the same issue, every strongswan doc about my intended setup says I need to set leftsourceip=%config (into ipsec.conf. which is .vips in swanctl.conf).

          As far as I understand I can't simply edit the strongswan config manually otherwise they would get overwritten. Could you provide any advice about hot to get this working?

          Restricting the local (pfsense side) site subnet to a single address in tunnel mode does not work because (as per strongswan doc's warning) that address is not installed on the tunnel. The VTI mode somehow "works" because that "local" address gets set on the virtual interface but the CHILD_SA local subnet is not getting restricted to that single address and ofc I can't restrict this from the remote responder since that phase2 conf is made to match many pfsense roadwarriors, not just a single one.

          S 1 Reply Last reply Reply Quote 1
          • S
            siegmarb @LuKePicci
            last edited by

            @lukepicci

            Just for reference, i raised a ticket:

            https://redmine.pfsense.org/issues/13788

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.