<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Site-2-Site with Cisco RV120W Wireless-N VPN Firewall]]></title><description><![CDATA[<p dir="auto">Hi guys,</p>
<p dir="auto">Please help me to solve the following issue. I have a KVM based pfSense cluster on one side and Cisco RV120W on the other one. Last SOHO from Cisco I've touched was 800 Series and it was quite good, CLI, IOS, show, debug... you know. The las one (RV1200W) doesn't provide an interface except some weird GUI and very basic IPSec configuration. Three times I made symmetric IPSec configuration with different crypto/digest parameters obtaining the same result: IPSec phase 1 comes up but no traffic going in/from the tunnel. Here is a relevant part of /var/etc/ipsec/<strong>ipsec.conf</strong> file</p>
<pre><code>conn con2000
        fragmentation = yes
        keyexchange = ikev1
        reauth = yes
        forceencaps = no
        mobike = no
        
        rekey = yes
        installpolicy = yes
        type = tunnel
        dpdaction = restart
        dpddelay = 10s
        dpdtimeout = 60s
        auto = route
        left = &lt;WAN_CARP VIP&gt;
        right = &lt;Cisco RV120 IP&gt;
        leftid = &lt;WAN_CARP VIP&gt;
        ikelifetime = 28800s
        lifetime = 3600s
        ike = aes128-sha256-modp1024!
        esp = aes128-sha256-modp1024!
        leftauth = psk
        rightauth = psk
        rightid = &lt;Cisco RV120 IP&gt;
        aggressive = no
        rightsubnet = 192.168.1.0/24
        leftsubnet = 10.0.0.0/14
</code></pre>
<p dir="auto">On the Cisco RV120 I have:<br />
<img src="/assets/uploads/files/1561308468613-1.png" alt="1.png" class=" img-fluid img-markdown" /> <img src="/assets/uploads/files/1561308468397-2.png" alt="2.png" class=" img-fluid img-markdown" /> <img src="/assets/uploads/files/1561308468208-3.png" alt="3.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/144379/site-2-site-with-cisco-rv120w-wireless-n-vpn-firewall</link><generator>RSS for Node</generator><lastBuildDate>Thu, 11 Jun 2026 15:59:05 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/144379.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 23 Jun 2019 16:47:50 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Site-2-Site with Cisco RV120W Wireless-N VPN Firewall on Tue, 25 Jun 2019 13:35:18 GMT]]></title><description><![CDATA[<p dir="auto">Hi guys,</p>
<p dir="auto">Any ideas why it doesn't work? What's the reason of appearing such logs in pfSense:</p>
<pre><code>Jun 23 12:49:06	charon		15[NET] &lt;con2000|28&gt; sending packet: from 154.61.34.210[500] to 195.177.74.126[500] (108 bytes)
Jun 23 12:49:06	charon		15[IKE] &lt;con2000|28&gt; activating new tasks
Jun 23 12:49:06	charon		15[IKE] &lt;con2000|28&gt; nothing to initiate
</code></pre>
<p dir="auto">Why there are no outgoing ESP packets from pfSense and why IPSec SA counters doesn't increased?</p>
]]></description><link>https://forum.netgate.com/post/850188</link><guid isPermaLink="true">https://forum.netgate.com/post/850188</guid><dc:creator><![CDATA[shshs]]></dc:creator><pubDate>Tue, 25 Jun 2019 13:35:18 GMT</pubDate></item><item><title><![CDATA[Reply to Site-2-Site with Cisco RV120W Wireless-N VPN Firewall on Mon, 24 Jun 2019 08:58:43 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/konstanti">@<bdi>Konstanti</bdi></a> said in <a href="/post/849903">Site-2-Site with Cisco RV120W Wireless-N VPN Firewall</a>:</p>
<blockquote>
<p dir="auto">tcpdump -netti enc0</p>
</blockquote>
<p dir="auto">While I'm pinging the destination behind the other site of the tunnel, I run tcpdump on enc0 and it doesn't show any relevant information, just traffic from the other IPSec VPNs.</p>
]]></description><link>https://forum.netgate.com/post/849907</link><guid isPermaLink="true">https://forum.netgate.com/post/849907</guid><dc:creator><![CDATA[shshs]]></dc:creator><pubDate>Mon, 24 Jun 2019 08:58:43 GMT</pubDate></item><item><title><![CDATA[Reply to Site-2-Site with Cisco RV120W Wireless-N VPN Firewall on Mon, 24 Jun 2019 08:16:03 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/shshs">@<bdi>shshs</bdi></a><br />
try to start <strong>tcpdump</strong> on the <strong>enc0</strong> interface<br />
for example<br />
<strong>tcpdump -netti enc0</strong><br />
what it shows ?</p>
<p dir="auto"><img src="/assets/uploads/files/1561364152154-cc3952e7-389f-4cf8-8349-9b6caa714437-image.png" alt="cc3952e7-389f-4cf8-8349-9b6caa714437-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/849903</link><guid isPermaLink="true">https://forum.netgate.com/post/849903</guid><dc:creator><![CDATA[Konstanti]]></dc:creator><pubDate>Mon, 24 Jun 2019 08:16:03 GMT</pubDate></item><item><title><![CDATA[Reply to Site-2-Site with Cisco RV120W Wireless-N VPN Firewall on Mon, 24 Jun 2019 07:19:27 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/konstanti">@<bdi>Konstanti</bdi></a><br />
I have such rule, it's not the cause of the problem.</p>
]]></description><link>https://forum.netgate.com/post/849901</link><guid isPermaLink="true">https://forum.netgate.com/post/849901</guid><dc:creator><![CDATA[shshs]]></dc:creator><pubDate>Mon, 24 Jun 2019 07:19:27 GMT</pubDate></item><item><title><![CDATA[Reply to Site-2-Site with Cisco RV120W Wireless-N VPN Firewall on Mon, 24 Jun 2019 06:20:47 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/shshs">@<bdi>shshs</bdi></a></p>
<p dir="auto">Hey<br />
Check the firewall rules on the IPSEC interface (PFSense side)</p>
<p dir="auto"><img src="/assets/uploads/files/1561357098395-6019db6e-d842-4d2e-98d8-7c791a873a95-image.png" alt="6019db6e-d842-4d2e-98d8-7c791a873a95-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">For example</p>
<p dir="auto"><img src="/assets/uploads/files/1561357243793-de72e5d0-fa81-4234-892c-202cca27d511-image.png" alt="de72e5d0-fa81-4234-892c-202cca27d511-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/849895</link><guid isPermaLink="true">https://forum.netgate.com/post/849895</guid><dc:creator><![CDATA[Konstanti]]></dc:creator><pubDate>Mon, 24 Jun 2019 06:20:47 GMT</pubDate></item><item><title><![CDATA[Reply to Site-2-Site with Cisco RV120W Wireless-N VPN Firewall on Sun, 23 Jun 2019 17:16:16 GMT]]></title><description><![CDATA[<p dir="auto">When I try to ping the destination behind the Cisco router I don't see child SA counters increase, sometimes there are 2 IPSec SA created at a time:<br />
<img src="/assets/uploads/files/1561310045428-screen-shot-2019-06-23-at-8.12.27-pm-resized.png" alt="Screen Shot 2019-06-23 at 8.12.27 PM.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">In IPSec logs on pfSense I get:</p>
<pre><code>Jun 23 12:49:01	charon		11[IKE] &lt;con2000|28&gt; nothing to initiate
Jun 23 12:49:02	charon		15[CFG] vici client 2141 connected
Jun 23 12:49:02	charon		11[CFG] vici client 2141 registered for: list-sa
Jun 23 12:49:02	charon		11[CFG] vici client 2141 requests: list-sas
Jun 23 12:49:02	charon		11[CFG] vici client 2141 disconnected
Jun 23 12:49:03	charon		15[NET] &lt;con1000|26&gt; received packet: from 38.142.65.154[500] to 154.61.34.210[500] (76 bytes)
Jun 23 12:49:03	charon		15[ENC] &lt;con1000|26&gt; parsed INFORMATIONAL request 4746 [ ]
Jun 23 12:49:03	charon		15[ENC] &lt;con1000|26&gt; generating INFORMATIONAL response 4746 [ ]
Jun 23 12:49:03	charon		15[NET] &lt;con1000|26&gt; sending packet: from 154.61.34.210[500] to 38.142.65.154[500] (76 bytes)
Jun 23 12:49:06	charon		15[NET] &lt;con2000|28&gt; received packet: from 195.177.74.126[500] to 154.61.34.210[500] (108 bytes)
Jun 23 12:49:06	charon		15[ENC] &lt;con2000|28&gt; parsed INFORMATIONAL_V1 request 3823163103 [ HASH N(DPD) ]
Jun 23 12:49:06	charon		15[IKE] &lt;con2000|28&gt; queueing ISAKMP_DPD task
Jun 23 12:49:06	charon		15[IKE] &lt;con2000|28&gt; activating new tasks
Jun 23 12:49:06	charon		15[IKE] &lt;con2000|28&gt; activating ISAKMP_DPD task
Jun 23 12:49:06	charon		15[ENC] &lt;con2000|28&gt; generating INFORMATIONAL_V1 request 2486254723 [ HASH N(DPD_ACK) ]
Jun 23 12:49:06	charon		15[NET] &lt;con2000|28&gt; sending packet: from 154.61.34.210[500] to 195.177.74.126[500] (108 bytes)
Jun 23 12:49:06	charon		15[IKE] &lt;con2000|28&gt; activating new tasks
Jun 23 12:49:06	charon		15[IKE] &lt;con2000|28&gt; nothing to initiate
</code></pre>
<p dir="auto">On Cisco's side I see the tunnel up and running, and when try to initiate ESP traffic from that side I see increasing Tx counters on Cisco's IPSec status.<br />
<img src="/assets/uploads/files/1561310060856-shh.png" alt="Shh.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">On pfSense tcpdump I receive incoming ESP from Cisco, but I don't see any outgoing ESP packets toward Cisco.</p>
<p dir="auto">Here is <strong>ipsec statusall</strong> output from the pfSense:</p>
<pre><code>[$]/root: ipsec statusall
Status of IKE charon daemon (strongSwan 5.7.1, FreeBSD 11.2-RELEASE-p10, amd64):
  uptime: 46 hours, since Jun 21 14:43:34 2019
  worker threads: 11 of 16 idle, 5/0/0/0 working, job queue: 0/0/0/0, scheduled: 6
  loaded plugins: charon unbound aes des blowfish rc2 sha2 sha1 md4 md5 random nonce x509 revocation constraints pubkey pkcs1 pkcs7 pkcs8 pkcs12 pgp dnskey ...
Listening IP addresses:
....
Connections:
   bypasslan:  %any...%any  IKEv1/2
   bypasslan:   local:  uses public key authentication
   bypasslan:   remote: uses public key authentication
   bypasslan:   child:  10.0.11.0/24|/0 === 10.0.11.0/24|/0 PASS
     con2000:  &lt;WAN-CARP VIP&gt;...&lt;Cisco IP&gt;  IKEv1, dpddelay=10s
     con2000:   local:  [&lt;WAN-CARP VIP&gt;] uses pre-shared key authentication
     con2000:   remote: [&lt;Cisco IP&gt;] uses pre-shared key authentication
     con2000:   child:  10.0.0.0/14|/0 === 192.168.1.0/24|/0 TUNNEL, dpdaction=restart
Shunted Connections:
   bypasslan:  10.0.11.0/24|/0 === 10.0.11.0/24|/0 PASS
Routed Connections:
     con2000{64}:  ROUTED, TUNNEL, reqid 4
     con2000{64}:   10.0.0.0/14|/0 === 192.168.1.0/24|/0
Security Associations (2 up, 0 connecting):
     con2000[28]: ESTABLISHED 38 minutes ago, &lt;WAN-CARP VIP&gt;[&lt;WAN-CARP VIP&gt;]...&lt;Cisco IP&gt;[&lt;Cisco IP&gt;]
     con2000[28]: IKEv1 SPIs: 2316dd2784d9bdac_i* 261b4138e97f82d0_r, pre-shared key reauthentication in 7 hours
     con2000[28]: IKE proposal: AES_CBC_128/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024
     con2000{62}:  INSTALLED, TUNNEL, reqid 4, ESP SPIs: c0a9a6e0_i 0675a2f5_o
     con2000{62}:  AES_CBC_128/HMAC_SHA2_256_128/MODP_1024, 0 bytes_i (0 pkts, 2336s ago), 0 bytes_o, rekeying in 4 minutes
     con2000{62}:   10.0.0.0/14|/0 === 192.168.1.0/24|/0
[$]/root: 
</code></pre>
<p dir="auto">What could it be, what do you suggest to test in addition?</p>
]]></description><link>https://forum.netgate.com/post/849839</link><guid isPermaLink="true">https://forum.netgate.com/post/849839</guid><dc:creator><![CDATA[shshs]]></dc:creator><pubDate>Sun, 23 Jun 2019 17:16:16 GMT</pubDate></item></channel></rss>