Solved: Issue with Cisco ASA - Single Traffic Selector per Child SA
-
Re: Issue with multiple P2 phases using NAT/BINAT on pfSense
I’d like to share how I resolved the issue with the tunnel between pfSense and a Cisco ASA device. The problem was that Cisco ASA only supports a single traffic selector per Child SA, which caused the tunnel to malfunction.
Solution:
In the Phase 1 settings on pfSense, I needed to check the "Split connections" option. After applying this change, the tunnel started working correctly.I hope this helps anyone facing a similar issue!
This version is clear, professional, and concise, ensuring the solution is easy to understand for others.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.