Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfSense 2.2 vs DrayTek (Need Help with error)

    Scheduled Pinned Locked Moved IPsec
    4 Posts 3 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V Offline
      VirtualDreams
      last edited by

      Hello,

      I'm having this error, and I can't seem to understand since I'm pretty much new in VPN's…

      http://pastebin.com/AUzR7Aku

      I followed the specific Guide, but it's not working...

      http://www.vaines.org/pfsense-to-draytek-ipsec-vpn/

      Any kind soul somewhere in here to help me with the troubleshooting?

      1 Reply Last reply Reply Quote 0
      • E Offline
        eri--
        last edited by

        Jan 30 14:54:18 charon: 13[CFG] looking for pre-shared key peer configs matching pFsense_PUBIP…DRAYTEK_PUBIP[192.168.30.2]
        Jan 30 14:54:18 charon: 13[IKE] <114> no peer config found

        1 Reply Last reply Reply Quote 0
        • C Offline
          cmb
          last edited by

          I left a comment on that blog post with some inaccuracies in their recommendations. Specifically:

          "Three issues with the suggestions here that I wanted to note, as they may cause people problems.

          One, it's almost never a good idea to enable "prefer old SAs", and isn't necessary with Drayteks that I've seen. It could cause problems to enable that, I wouldn't recommend it.

          Two, on "Call Direction" on Draytek, it should almost always be set to "Both" otherwise the remote side can't initiate the IPsec.

          Three, the "Local Network IP" part should be the network address, not an IP within the subnet. So for the example shown here, it should be 192.168.2.0 not 2.254. "

          Though your problem looks to be outside of any of that, it appears you're using mismatched identifiers on phase 1, sending the private WAN IP of the Draytek across.

          1 Reply Last reply Reply Quote 0
          • V Offline
            VirtualDreams
            last edited by

            Hi, thanks for the replys…

            I'll be doing this changes this afternoon, and I'll leave a feedback. Thanks for the help

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.