Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiple VTI IPSEC tunnels with /30 on same 192.168.X.0 ?

    Scheduled Pinned Locked Moved IPsec
    2 Posts 2 Posters 411 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Y
      Yathus
      last edited by

      Hello,

      I have a pfsense 2.4.5 in my datacenter, it handle multiple ipsec site-2-site tunnels.
      i tried to use a /30 for 2 of them and it break everything.

      Example for P2 :
      siteA : 192.168.34.1/30 -> siteB 192.168.34.2/30
      siteA: 192.168.34.5/30 -> siteC 192.168.34.6/30

      With these configuration i can't have both tunnel up, it's siteA <-> siteB or siteA <-> siteC

      To fix these i have to change adresse used in P2 :
      siteA : 192.168.49.1/30 -> siteB 192.168.49.2/30
      siteA: 192.168.34.5/30 -> siteC 192.168.34.6/30

      did i miss something ?

      May be it's because one my client is not on latest version ? (2.4.4-p2)

      Thanks

      Yathus

      jimpJ 1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate @Yathus
        last edited by

        @yathus said in Multiple VTI IPSEC tunnels with /30 on same 192.168.X.0 ?:

        May be it's because one my client is not on latest version ? (2.4.4-p2)

        That is likely the case. Some older versions didn't properly respect the configured subnet mask for VTI interfaces. Update both to a current version and try again.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.