Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IP SEC : Pfsense <-> watchguard BOVPN

    Scheduled Pinned Locked Moved IPsec
    2 Posts 1 Posters 966 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Y
      yguerchet
      last edited by yguerchet

      Hello,

      I have an IPsec tunnel mounted between a pfsense firewall and a watchguard (bovpn) firewall. The two firewalls are configured in exactly the same way:

      Phase 1 :
      Key Exchange version : IKEv2
      Auth method : Mutual PSK
      My identifier : My IP address
      Peer identifier : Peer IP address
      Encryption:

      • Algo : AES
      • Key lenght 128bits
      • Hash : SHA256
      • DH Group 14 (2048 bits)

      Life Time : 28800

      Phase 2 :

      Mode : tunnel IPV4
      Protocole : ESP
      Encryption Algo : AES 128 bits
      Hash Algo : SHA256
      PFS key group : 14 (2048 bit)
      Life Time : 28800
      Rekey Tume : 25200

      Phase 1 is working perfectly. The problem comes from phase 2, when phase 2 is initialized (thanks to a ping for example from the network on the watchguard side to the Pfsense network) phase 2 goes up well. But when the ping is in the opposite direction (Pfsense network to the watchguard network, the ping does not work and phase 2 does not start). We can not find any log of attempt to initiate on the side of watchguard or pfsense.
      The watchguard firewall does allow ports 500 and 4500. And the ESP protocol.

      Can you explain to me why it works one way and not the other? Thank you in advance for your help.

      Y 1 Reply Last reply Reply Quote 0
      • Y
        yguerchet @yguerchet
        last edited by

        @yguerchet The topic is old, but i solved it. By enabling "split connection"

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.