Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Site to site ipsec vpn with two pfsense boxes 2.0 RC1 and certificates

    Scheduled Pinned Locked Moved IPsec
    17 Posts 2 Posters 10.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      eazydor
      last edited by

      @pfsenseuser when setting the identifiers to asn.1 could you restart racoon?

      1 Reply Last reply Reply Quote 0
      • P
        pfsenseuser3
        last edited by

        no, when i set my and peer identifier to asn.1 all vpn connections were offline.. even the vpn connection (with pre shared key) which was working before.

        could you please tell me how do you created the certificates? step by step..

        edit: here is also a screen ->

        "pfsense1" are the CA and certificate from the other box. On the other box i created them in the Cert Manager, downloaded them and imported it on this box.

        for this i also got no answer. PLEASE Help.

        1 Reply Last reply Reply Quote 0
        • E
          eazydor
          last edited by

          consider this:
          https://portal.pfsense.org/index.php/support-subscription

          1 Reply Last reply Reply Quote 0
          • P
            pfsenseuser3
            last edited by

            why you can´t tell me if i did something wrong with the certificates? It seems you already have them..

            1 Reply Last reply Reply Quote 0
            • E
              eazydor
              last edited by

              system -> cert manager
              CA
              add ca
              method create ca
              fill out details
              Certificates
              add certificates
              create internal cert
              fill out details

              you can't expect people to do all the work for you, man..

              1 Reply Last reply Reply Quote 0
              • P
                pfsenseuser3
                last edited by

                thx.. i do not expect that you do all work for me, i only wanted to know if i did it right.

                but again you didn´t  completly answered my question…

                Let´s say i have router A and router B.

                as you wrote i create the CA and certificates on A and B. That i have already done.

                But now i have to export the CA and certificates from A and B and import on the other side.. or?
                So that the CA and certificate from A is on B and backwards.

                Than on A i set My certificate and My certificate authority to the CA and Certificate from B and backwards..
                Please tell me if this is the right way..

                Thanks a lot!!

                1 Reply Last reply Reply Quote 0
                • E
                  eazydor
                  last edited by

                  wrong way. you just have one certificate authority.

                  1 Reply Last reply Reply Quote 0
                  • P
                    pfsenseuser3
                    last edited by

                    hmm ok.. with the ipcop i had different CA´s, so i also tried it here.

                    Please tell me the right way.. at the moment your answers are not really helpfull.. very bad answers from you.
                    if you know a good tutorial you can post the link

                    1 Reply Last reply Reply Quote 0
                    • P
                      pfsenseuser3
                      last edited by

                      it´s now working for me with this warnings

                      May 2 14:37:22 	racoon: WARNING: unable to get certificate CRL(3) at depth:0 SubjectName:/C=AT/ST=xxx/L=xxxx/O=Traussnig/emailAddress=xxx/CN=internal-ca
                      May 2 14:37:22 	racoon: WARNING: unable to get certificate CRL(3) at depth:1 SubjectName:/C=AT/ST=xxx/L=xxx/O=Traussnig/emailAddress=xxx/CN=internal-ca
                      

                      does anyone know what this means?

                      1 Reply Last reply Reply Quote 0
                      • E
                        eazydor
                        last edited by

                        racoon failed to lookup a certificate revocation list.

                        1 Reply Last reply Reply Quote 0
                        • P
                          pfsenseuser3
                          last edited by

                          so i can ignore this warning? i need no revocation list.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.