<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Multiple VTI IPSEC tunnels with &#x2F;30 on same 192.168.X.0 ?]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">I have a pfsense 2.4.5 in my datacenter, it handle multiple ipsec site-2-site tunnels.<br />
i tried to use a /30 for 2 of them and it break everything.</p>
<p dir="auto">Example for P2 :<br />
siteA : 192.168.34.1/30 -&gt; siteB 192.168.34.2/30<br />
siteA: 192.168.34.5/30  -&gt; siteC 192.168.34.6/30</p>
<p dir="auto">With these configuration i can't have both tunnel up, it's siteA &lt;-&gt; siteB or siteA &lt;-&gt; siteC</p>
<p dir="auto">To fix these i have to change adresse used in P2 :<br />
siteA : 192.168.49.1/30 -&gt; siteB 192.168.49.2/30<br />
siteA: 192.168.34.5/30  -&gt; siteC 192.168.34.6/30</p>
<p dir="auto">did i miss something ?</p>
<p dir="auto">May be it's because one my client is not on latest version ? (2.4.4-p2)</p>
<p dir="auto">Thanks</p>
<p dir="auto">Yathus</p>
]]></description><link>https://forum.netgate.com/topic/159679/multiple-vti-ipsec-tunnels-with-30-on-same-192-168-x-0</link><generator>RSS for Node</generator><lastBuildDate>Mon, 15 Jun 2026 14:48:42 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/159679.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 06 Jan 2021 07:14:23 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Multiple VTI IPSEC tunnels with &#x2F;30 on same 192.168.X.0 ? on Wed, 06 Jan 2021 13:28:24 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/yathus">@<bdi>yathus</bdi></a> said in <a href="/post/955285">Multiple VTI IPSEC tunnels with /30 on same 192.168.X.0 ?</a>:</p>
<blockquote>
<p dir="auto">May be it's because one my client is not on latest version ? (2.4.4-p2)</p>
</blockquote>
<p dir="auto">That is likely the case. Some older versions didn't properly respect the configured subnet mask for VTI interfaces. Update both to a current version and try again.</p>
]]></description><link>https://forum.netgate.com/post/955311</link><guid isPermaLink="true">https://forum.netgate.com/post/955311</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Wed, 06 Jan 2021 13:28:24 GMT</pubDate></item></channel></rss>