• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How do I disable two IPSec clients from connecting with the same credentials?

Scheduled Pinned Locked Moved IPsec
1 Posts 1 Posters 371 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    rsraney
    last edited by Dec 15, 2017, 7:29 PM Dec 7, 2017, 8:26 PM

    First off, my experience with pfSense is weak at best. I manage a few external Strongswan VPN gateways for a QA team and looking into pfSense to help diminish my overhead between configurations and deployment of testing services.  Any help or suggestions would be great.

    Here is a summary of the issues I am seeing. I will attempt to use Strongswan's nomenclature.

    IPSec VPN Gateway Server:  Moon
    Android Device-1: Client-1 (User Tom credentials)
    Android Device-2: Client-2 (User Tom credentials)
    IP Pool for VPN 192.168.102.0/24
    Internal network 10.0.10.0/24

    All tests have been performed using WiFi AP (with NAT)  and via cellular carriers.

    Steps to reproduce the issue:
    1)    When Client-1 is connected to Moon and receives the IP 192.168.102.1 and can access all network resources successfully
    2)  If Client-2 is authenticated using same credentials as Client-1 to Moon, it will be assigned  IP 192.168.65.2 and can access all network resources successfully.

    After second connection, Client-1 is still connected to the VPN but suddenly will not able to network resources, but Client-2  can access all network resources internal and external successfully.

    What my team and myself expect Client-1 and Client-2 can never be connected at the same time if they use the same authentication.  The last successful authentication client will force a disconnect any existing connections using the same credentials.

    I have a working version of this in Ubuntu using Strongswan VPN, and I use 'uniqueids=yes' to perform this.  I've enabled the 'uniqueids' to 'yes' in the advanced menu, but I still see the same problem.

    1 Reply Last reply Reply Quote 0
    1 out of 1
    • First post
      1/1
      Last post
    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
      This community forum collects and processes your personal information.
      consent.not_received