pfSense creating multiple P2 (child SA) entries



  • We have been having an issue with the IKEv2 protocol creating multiple child SA (p2) entries everytime the lifetime is renewed.

    We have observed this issue with both the Pfsense version 2.4.3-RELEASE-p1 (amd64) & v2.3.5.

    This is a site-to-site IPsec VPN setup between pfSense to Strongswan. The Strongswan is located in the Amazon Ec2 instance using Amazon Linux 2 OS.(StrongSwan U5.6.3/K4.14.62-70.117.amzn2.x86_64)

    Attaching the configuration & logs of both the ends. 6_1542901656440_Phase1_Part1.png 5_1542901656440_Phase1_Part2.png 4_1542901656440_Phase2_Part 2.png 3_1542901656440_VPN_IPsec.png 2_1542901656440_Phase 2_Part1.png 1_1542901656439_IPSec status.png 0_1542901656437_Strongswan configuration.png
    0_1542902059807_Pfsense Ipsec Logs.txt
    0_1542902084215_Strongswan Logs.txt.gz

    PS: The Public IP mentioned in the logs will is not the original one as I have changed it for security reasons.



  • Hey guys,

    We still continue to have the problem. Can you please help?

    Regards,
    Vijay Rao