• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Phase 1 proposal (authentication) only Mutual Certificate/PSK available

Scheduled Pinned Locked Moved IPsec
4 Posts 2 Posters 699 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    tlarimer
    last edited by Mar 31, 2023, 1:03 AM

    I have a SG-1100, operating on 23.01, I am trying to clone my existing VPN's from two other configured and working installations and when I start setting up phase 1 authentication, my only two options are Mutual certificate and Mutual PSK. On my other two appliances I have many other options.

    I am almost certain this is operator error, but what exactly do I need to do to enable the rest of the options? I have seen this question posted a few places and there is never any answer. I have restored the SG-1100 to factory settings a few times, installed the patches package and installed recommended patches.

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Mar 31, 2023, 1:17 PM

      Site-to-site tunnels are only Mutual certificate or PSK.

      A mobile IPsec tunnel can use more/different authentication options but you can only have one mobile tunnel.

      The one you are trying to copy might be a mobile setup which is a bit different to setup than site-to-site. You have to enable it on the mobile tab and create the P1 using the button it will offer you once that's enabled.

      See https://docs.netgate.com/pfsense/en/latest/recipes/ipsec-mobile-ikev2-eap-mschapv2.html for a whole walk-through

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      T 2 Replies Last reply Mar 31, 2023, 1:29 PM Reply Quote 1
      • T
        tlarimer @jimp
        last edited by Mar 31, 2023, 1:29 PM

        @jimp that actually makes a lot of sense, I am setting up a mobile vpn to my other house.

        I will give it a try this afternoon when I am back in front of the netgate device and report back.

        Thank you for the assist

        1 Reply Last reply Reply Quote 0
        • T
          tlarimer @jimp
          last edited by Mar 31, 2023, 9:36 PM

          @jimp Thank you sir, that did the trick, after I setup mobile config, applied settings and saved the authentication fields appeared.

          Much appreciate the assist sir.

          1 Reply Last reply Reply Quote 1
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received