help to solve ipsec problem
-
hi to all and thanks in advance....
this is my situation:
a: pfsense ipsec
b: dryteklog pfsense:
-
@Giorgio-Dutto
what is sticking out to me is thisThis is a site2site IPsec VPN?
Can you provide the config for each site? -
-
A few things stick out.
- The drytek is sitting behind a NAT device. So in pfsense when you select Peer Identifier make sure you put in the real Source IP of the gateway. For example 192.168.1.2 (whatever it is pre-nat)
- pfSense is using pfs group14 for phase2. Although i see the drytek configuration selected to use PFS which key value is it using? Does it default to group14?
- Phase2 lifetimes appear to be mismatched. pfsense is set to 86400s while the drytek is set for 600s
In the pfsense GUI, do you see p1 established? P2 is the one that is failing? Not sure where in the process things break down.
-
@michmoor
Great!!!it was exactly the "Peer Identifier"
now the only thing I can't do is see all the subnets of the remote site....I added the second subnet but I don't see it.
-
@Giorgio-Dutto
Note that a /24 network address ends with ".0". As well the network settings in the phase 2 of both sites have to match.
So you need to correct this on the Drytek. -
@viragomann
Ops!
Thanks will correct