VPN IPSEC not Working even tho Phase 1 and Phase 2 are established
-
Hello...
I just configured a IPSEC VPN with Phase 1 and Phase 2, working.
The Local Subnet on Phase 2 is a Virtual IP that is pointed to a internal IP of mine (Which is working, if i try to access using the Local Network - Not the IPSEC), and the remote subnet is a local IP address of the remote side.But even tho Phase 2 is established, it is not working.
Please, can someone help me?Below some images showing the configuration:
- Phase 2 Configuration
- Ping from the Remote Subnet to Local Subnet (Not Working)
What could i do to understand this better?
Is there something else i need to do in pfSense to make this work? -
Those subnets look like single IP addresses and not the IP you are trying to ping.
What IP are you trying to ping from?
What is the P2 config there?
Steve
-
@stephenw10 said in VPN IPSEC not Working even tho Phase 1 and Phase 2 are established:
Those subnets look like single IP addresses and not the IP you are trying to ping.
What IP are you trying to ping from?
What is the P2 config there?
Steve
Hi. The weirdest thing is that i can ping from inside pfSense 192.168.1.248, but from the Remote Subnet comm isnt working. Just from pfSense...
The image is: Remote Subnet doing a ping on Local Subnet (Phase 2!)
Ping from Local Subnet to Remote Subnet works, but the opposite doesnt.I'm trying to ping from 192.168.1.248 (Remote Subnet) to 172.16.250.10 (The image was 172.16.200.10 but it was a type, below a image with same result on the correct IP)
-
But what is the source IP address there where the ping is failing?
What subnets are defined in the IPSec P2 config?
-
@stephenw10 said in VPN IPSEC not Working even tho Phase 1 and Phase 2 are established:
But what is the source IP address there where the ping is failing?
What subnets are defined in the IPSec P2 config?
Phase 2 is only :
Remote Subnet: 192.168.1.248 Local Subnet: 172.16.250.10
Ping from Local > Remote = OK.
Ping from Remote > Local = Fail. -
@raulchiarella said in VPN IPSEC not Working even tho Phase 1 and Phase 2 are established:
But what is the source IP address there where the ping is failing?
-
It looks like it isn't 192.168.1.248 because pfSense has that IP. So it doesn't match the traffic and the ping fails.