Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiple IPsec VPN's terminating at one location

    Scheduled Pinned Locked Moved IPsec
    4 Posts 2 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pnutjam
      last edited by

      I am trying to do something I though would be simple.  I have configured 3 VPN's on my head unit and each other unit only has one of those VPN's configured on them.  I had two working simultaniously, but all three do not work.  Now I can't even get three to work.

      When I have multiple VPN's configured on one box I assume I need to specify a different identifier for each one?  Do I need to put identifiers and psk's in for each static connection?  It doesn't seem to be necessary if you are using the IP of the box on each end.  The only connection that seems to work consistantly is the one using the IP of the main box as it's identifier.  If I set another connection to use the IP of the main box as it's identifier also, it seems to cause problems.  Using Domain names does not seem to work.

      All IP's are static I think my problem is really linked to Identifiers and PSK's.  Could somebody please clarify what is needed?

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        In case you have static IPs everywhere use "my IP Adress" as identifier everywhere. The PSK can be different but doesn't need to be. I have more tunnels than you have running at a location, some even joining from dynamic IPs (howto do that see http://pfsense.com/mirror.php?section=tutorials/mobile_ipsec/ ) and some even from non pfSense systems.

        1 Reply Last reply Reply Quote 0
        • P
          pnutjam
          last edited by

          If I do this I can have more then one tunnel on the head box using "my IP" as the identifier?  Can I also have different PSK's on these?

          Thanks for the prompt reply :)

          1 Reply Last reply Reply Quote 0
          • H
            hoba
            last edited by

            Yep, you can.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.