IPSEC VPN
-
After creation and connection, ipsec VPN status shows one phase1 and two phase 2 connection.
-
Impossible to say without more information there but that's not necessarily a problem.
Can we assume that there is only one phase 2 config?
If it's set to make before break for example that can still be fine. As long as it moves traffic to the new SA after it's created.
Steve
-
If you just see two, it's probably OK and a normal part of (re)negotiation depending on which side does what.
If you get more and they start piling up, then you might need to adjust the settings:
https://docs.netgate.com/pfsense/en/latest/troubleshooting/ipsec-duplicate-sa.html
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.