Tunneling between IPsec -> Traffic selector wrong
-
Hi,
i have two IPsec tunnels between two different locations. The Netgate is in between both, and should allow the traffic from Location A to flow to Location B.
I have IPsec Tunnels to both sites, and Phase1 as Phase2 is up and running.
To access the Network on Site B, i do NAT all SAs on a virtual IP. So the traffic that flows in Site B appears with a source IP of the NATed IP.So far so good. The only issue that I have is multiple Child SAs, and what is very strange, the traffic selection is done wrong. The local subnet that is show and used for the child SA is somehow randomly choosen, and not linked to the network where the traffic is coming from. When there are double child SAs there is no traffic flow anymore thru the tunnel, as long as their is a dublicate. I might have two issues here.
I have some difficulties to explain myself here. So maybe this helps:
Im going to ping from 10.47.72.80 to 10.170.47.1. The ping is going thru. But the only active SA is:
P2 config:
P2 NAT:
When I disable the 172.31.0.0 P2, another random subnet is picked and shown as traffic selector.