• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPSec Phase 2 local network & access from LAN

Scheduled Pinned Locked Moved IPsec
2 Posts 1 Posters 491 Views 1 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G Offline
    GoneCamping
    last edited by GoneCamping Jan 19, 2021, 5:19 PM Jan 19, 2021, 5:18 PM

    A bit of an experienced newb here.

    We are establishing an IPSec connection with a customer. In short, I was only able to get P2 to come up when I used the WAN IP as the local network/address. Our WAN IP is used as part of the authentication process, it would seem (NO_PROPOSAL_CHOSEN was the error when I had our LAN as the local network).

    What this seems to mean in practice is that I can ping their network from WAN (traffic shows up in the IPSec status), but not from a computer on my LAN. How do I establish the connection between WAN/LAN so that I can pass traffic from LAN to the customer network?

    When setting up our inter-office IPSec tunnels this wasn't a problem because we're able to choose our local/remote network IPs. Our customer is so large that they don't have that luxury.

    Thank you!

    G 1 Reply Last reply Jan 19, 2021, 6:22 PM Reply Quote 0
    • G Offline
      GoneCamping @GoneCamping
      last edited by Jan 19, 2021, 6:22 PM

      @gonecamping

      I am a flipping idiot. ;-)

      If I put the WAN IP as the NAT/BINAT address and then LAN as the local network, it worked. P2 still works and traffic flows from LAN to our customer network.

      1 Reply Last reply Reply Quote 0
      2 out of 2
      • First post
        2/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received