Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Site-to-Site IPSec Tunnel With One Dynamic IP

    Scheduled Pinned Locked Moved IPsec
    5 Posts 2 Posters 837 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      Bert 0
      last edited by

      Hello,

      I have two Netgates (SG-2200 (static) and SG-1100 (dynamic)) that I would to connect via a site-to-site VPN connection. I tried to follow the instructions given in another thread but a) one end was a Lancom router; and b) the instructions didn't seem to fit my Netgate (different pfsence version? I'm running 23.01). Are there any instructions available for this situation?

      Thanks

      B 1 Reply Last reply Reply Quote 0
      • B
        Bert 0 @Bert 0
        last edited by

        @bert-0 Well, I sort of have it running. The P1 tunnel shows established at both ends and the P2 shows installed at both ends. Unfortunately, no traffic flows through the tunnel. Pings of remote hosts fails (request timed out) and tracert to a remote host shows a single hop to the local firewall and nothing after that.

        I have both ends configured in accordance with the instructions I can find. Is there something else I need to do?

        V 1 Reply Last reply Reply Quote 0
        • V
          viragomann @Bert 0
          last edited by

          @bert-0 said in Site-to-Site IPSec Tunnel With One Dynamic IP:

          Is there something else I need to do?

          There might be nobody be able to tell you this without knowing, what you did yet.

          Whatever, consider that network devices blocks access from remote site by default. You have to configure their firewall properly before to be able to access them.

          B 1 Reply Last reply Reply Quote 0
          • B
            Bert 0 @viragomann
            last edited by

            @viragomann Ture but I just set up a basic Netgate to Netgate IPSEC VPN. Both ends report that they see each other and that the tunnel is successfully established. Yet, no traffic can go through the tunnel. If I couldn't make the connection (which was my original problem), then your comment would make sense in my case.

            My suspicion at this point is that one of my ISPs is blocking the IPSEC traffic but I'm not sure how to prove that. Or, if true, why the tunnel would successfully complete in the first place.

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @Bert 0
              last edited by

              @bert-0
              As you wrote above, the IPSec status shows that the connection is established. So it might not be blocked at all.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.