Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Any plans to support Virtual Tunnel Interfaces (VTI) for IPSEC VPNs?

    Scheduled Pinned Locked Moved IPsec
    15 Posts 7 Posters 5.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • jimpJ Offline
      jimp Rebel Alliance Developer Netgate
      last edited by

      @jimp:

      Routed IPsec is on our radar, no specific time frame or implementation details though.

      Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • F Offline
        fredlubrano
        last edited by

        Hello Jimp

        I understand your answer, but this post date December 2015 when I thought meantime you had more news.
        This function is essential for choosing our future equipment.
        It is boring to choose a fortigate because pfsense Not VTI Routed IPsec . :'(

        Thanks for the reply

        Best regards,

        fred

        1 Reply Last reply Reply Quote 0
        • D Offline
          dimostin
          last edited by

          Hello guys,

          We have any news regarding Virtual Tunnel Interfaces (VTI) for IPSEC VPNs on PfSense equipments ?

          Regards,
          dimostin

          1 Reply Last reply Reply Quote 0
          • jimpJ Offline
            jimp Rebel Alliance Developer Netgate
            last edited by

            Not possible currently, but the code for VTI was recently imported to FreeBSD, so it is going to show up in a future version eventually.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • B Offline
              Brailyn
              last edited by

              +1 for this:)

              1 Reply Last reply Reply Quote 0
              • K Offline
                kholmqvist
                last edited by

                +1 :)

                1 Reply Last reply Reply Quote 0
                • jimpJ Offline
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  It will be in pfSense 2.5, which will be based on FreeBSD 12, which has the IPsec VTI code. No ETA on that though, probably at least a year out, likely more.

                  Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • T Offline
                    tweek
                    last edited by

                    Jim, what flavor of BGP will the new VTI code utilize, and would you be willing to add a module for the BIRD internet routing daemon?

                    1 Reply Last reply Reply Quote 0
                    • jimpJ Offline
                      jimp Rebel Alliance Developer Netgate
                      last edited by

                      It's too early to say for any of that. We are looking at FRR for all routing functionality though, no current plans for bird

                      Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      1 Reply Last reply Reply Quote 0
                      • T Offline
                        tweek
                        last edited by

                        If you could please consider BIRD for inclusion.ย  My router expert friend assures me BIRD is much more powerful and better architected than FRR.

                        1 Reply Last reply Reply Quote 0
                        • jimpJ Offline
                          jimp Rebel Alliance Developer Netgate
                          last edited by

                          @tweek:

                          If you could please consider BIRD for inclusion.ย  My router expert friend assures me BIRD is much more powerful and better architected than FRR.

                          Our router expert employees prefer FRR/Quagga and assure us it's better than BIRD in various ways.

                          Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                          Need help fast? Netgate Global Support!

                          Do not Chat/PM for help!

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.