<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IP SEC : Pfsense &lt;-&gt; watchguard BOVPN]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">I have an IPsec tunnel mounted between a pfsense firewall and a watchguard (bovpn) firewall. The two firewalls are configured in exactly the same way:</p>
<p dir="auto"><strong>Phase 1 :</strong><br />
Key Exchange version : IKEv2<br />
Auth method : Mutual PSK<br />
My identifier : My IP address<br />
Peer identifier : Peer IP address<br />
Encryption:</p>
<ul>
<li>Algo : AES</li>
<li>Key lenght 128bits</li>
<li>Hash : SHA256</li>
<li>DH Group 14 (2048 bits)</li>
</ul>
<p dir="auto">Life Time : 28800</p>
<p dir="auto"><strong>Phase 2 :</strong></p>
<p dir="auto">Mode : tunnel IPV4<br />
Protocole : ESP<br />
Encryption Algo : AES 128 bits<br />
Hash Algo : SHA256<br />
PFS key group : 14 (2048 bit)<br />
Life Time : 28800<br />
Rekey Tume : 25200</p>
<p dir="auto">Phase 1 is working perfectly. The problem comes from phase 2, when phase 2 is initialized (thanks to a ping for example from the network on the watchguard side to the Pfsense network) phase 2 goes up well. But when the ping is in the opposite direction (Pfsense network to the watchguard network, the ping does not work and phase 2 does not start). We can not find any log of attempt to initiate on the side of watchguard or pfsense.<br />
The watchguard firewall does allow ports 500 and 4500. And the ESP protocol.</p>
<p dir="auto">Can you explain to me why it works one way and not the other? Thank you in advance for your help.</p>
]]></description><link>https://forum.netgate.com/topic/164118/ip-sec-pfsense-watchguard-bovpn</link><generator>RSS for Node</generator><lastBuildDate>Thu, 05 Mar 2026 14:59:30 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/164118.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 01 Jun 2021 13:01:25 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IP SEC : Pfsense &lt;-&gt; watchguard BOVPN on Thu, 24 Mar 2022 15:54:48 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/yguerchet">@<bdi>yguerchet</bdi></a> The topic is old, but i solved it. By enabling "split connection"</p>
]]></description><link>https://forum.netgate.com/post/1034430</link><guid isPermaLink="true">https://forum.netgate.com/post/1034430</guid><dc:creator><![CDATA[yguerchet]]></dc:creator><pubDate>Thu, 24 Mar 2022 15:54:48 GMT</pubDate></item></channel></rss>