<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPsec IKEv2 with two P2 - traffic selectors unacceptable]]></title><description><![CDATA[<p dir="auto">Hello!</p>
<p dir="auto">I have two pfSense Boxes and trying to connect them via IPsec with IPv4 and IPv6, both.<br />
I set up IKEv2 P1 on both sides and two P2 on both sides. One for IPv4 and one for IPv6. The IPv4 tunnel works great but IPv6 wont establish a connection.<br />
The log shows that the traffic selectors are unacceptable. But I dont see the problem. Maybe anyone can help me with that?</p>
<p dir="auto">Here are some short log outputs:</p>
<p dir="auto"><strong>Site A (192.168.0.0/24 &amp; fd00::/112)</strong></p>
<pre><code>Jan 4 17:19:08	charon		12[CFG] &lt;con1000|4841&gt; proposing traffic selectors for us:
Jan 4 17:19:08	charon		12[CFG] &lt;con1000|4841&gt; 192.168.0.0/24|/0
Jan 4 17:19:08	charon		12[CFG] &lt;con1000|4841&gt; fd00::/112|/0
Jan 4 17:19:08	charon		12[CFG] &lt;con1000|4841&gt; proposing traffic selectors for other:
Jan 4 17:19:08	charon		12[CFG] &lt;con1000|4841&gt; 192.168.1.0/24|/0
Jan 4 17:19:08	charon		12[CFG] &lt;con1000|4841&gt; fd00::1:0/112|/0
Jan 4 17:19:31	charon		15[CFG] &lt;con1000|4841&gt; looking for a child config for 192.168.0.0/24|/0 fd00::/112|/0 === 192.168.1.0/24|/0 fd00::1:0/112|/0
Jan 4 17:19:31	charon		15[IKE] &lt;con1000|4841&gt; traffic selectors 192.168.0.0/24|/0 fd00::/112|/0 === 192.168.1.0/24|/0 fd00::1:0/112|/0 unacceptable
</code></pre>
<p dir="auto"><strong>Site B (192.168.1.0/24 &amp; fd00::1:0/112)</strong></p>
<pre><code>Jan 4 17:20:25	charon		10[CFG] &lt;con1000|29220&gt; proposing traffic selectors for us:
Jan 4 17:20:25	charon		10[CFG] &lt;con1000|29220&gt; 192.168.1.0/24|/0
Jan 4 17:20:25	charon		10[CFG] &lt;con1000|29220&gt; fd00::1:0/112|/0
Jan 4 17:20:25	charon		10[CFG] &lt;con1000|29220&gt; proposing traffic selectors for other:
Jan 4 17:20:25	charon		10[CFG] &lt;con1000|29220&gt; 192.168.0.0/24|/0
Jan 4 17:20:25	charon		10[CFG] &lt;con1000|29220&gt; fd00::/112|/0
</code></pre>
<p dir="auto">Thanks!</p>
<p dir="auto">Kind regards<br />
Malte</p>
]]></description><link>https://forum.netgate.com/topic/149422/ipsec-ikev2-with-two-p2-traffic-selectors-unacceptable</link><generator>RSS for Node</generator><lastBuildDate>Mon, 15 Jun 2026 14:30:54 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/149422.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 04 Jan 2020 16:33:30 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IPsec IKEv2 with two P2 - traffic selectors unacceptable on Mon, 06 Jan 2020 16:18:18 GMT]]></title><description><![CDATA[<p dir="auto">What do the lines for the network(s) look like in <code>/var/etc/ipsec/ipsec.conf</code> on both sides?</p>
<p dir="auto">What does <code>ipsec statusall</code> show on both sides?</p>
<p dir="auto">This is probably one of many things fixed by the IPsec swanctl conversion on 2.5.0, but you may not want to make that leap on production systems yet.</p>
]]></description><link>https://forum.netgate.com/post/884147</link><guid isPermaLink="true">https://forum.netgate.com/post/884147</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Mon, 06 Jan 2020 16:18:18 GMT</pubDate></item></channel></rss>