IPsec over VIP CARP IP
-
I'am trying estableshed a VPN site-to-site IPsec between a normal pfSense and a CARP VIP. I tried configure the ipsec to use a VIP but she don't connect. I'm saw some posts, and I read the docs about it but don't achived replicate.
I'm did the ipsec configuration tunnel on master CARP fw, on peers identifier i adding "IP addresses" and add the VIP as peer identifier of tunnel, but nothing worked. The two points have communication, no fw rules, just have a NAT on CARP to point the traslate of LAN to VIP, but i think that this is not a problem. I don't know if I right undersant as doing it, if someone can help me I thanks.
Thanks in advanced.
Networks:
pfSense:
LAN - 10.128.24.0/24 WAN - 192.168.23.130/25
pfSense100:
(NAT - LAN > VIPWAN) LAN - 172.16.20.1/24 WAN - 192.168.23.1/25 VIP(WAN) - 192.168.23.10/25 VIP(LAN) - 172.16.20.1/24
pfSense200
(NAT - LAN > VIPWAN) LAN - 172.16.20.2/24 WAN - 192.168.23.2/25 VIP(WAN) - 192.168.23.10/25 VIP(LAN) - 172.16.20.1/24
The diagram:
pfSense200(Master) configuration:
-
@T2M5 You can't use those IPs in the Internet, those are RFC1918 IPs.
Also, click Generate new Pre-Shared Key, don't set it by yourself. -
@mcury said in IPsec over VIP CARP IP:
RFC1918
Hi mcury, thanks to reply.
I off the "Block private networks" and "Block Bogon networks" rules, than I no think that is the problem, unless that ipsec don't permit private IPS, but I have done others ipsec configurations with privates ips on labs. And about the PSK, is only a simple test lab environment.
-
you can't use e0's IP address there, you need to use the router's e0/1 IP address.
If it goes through the Internet, you must use the public IP for the IPsec. -
@mcury interesting, but the router are servin just a routing, it don't have NAT or something. My intention is seal a connection between pfSenses, the router is tecnicaly invisible, i placed he there just to don't connect the two fw directly. I maybe misundersant what did say, i'm sorry if was this.
-
@T2M5 ok, I thought that this was going through the Internet and you were using invalid IPs for that purpose.
There, select the VIP.
You mentioned NAT, check if you followed the instructions correctly:
-
-
@T2M5 said in IPsec over VIP CARP IP:
Thanks a lot for the help, have a great day bro.
glad that it worked, good day for you too bro