<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[GRE+IPsec transport mode with Cisco router]]></title><description><![CDATA[<p dir="auto">Hello everyone,<br />
I am trying to establish tunnel between pfsense 2.6.0 and Cisco router. Using GRE+IPsec ikev2 in transport mode . Phase1 is OK, connection established but phase2 unable to connect. In log there are messages</p>
<pre><code>15[IKE] &lt;con2|352&gt; establishing CHILD_SA con2{25048}
15[ENC] &lt;con2|352&gt; generating CREATE_CHILD_SA request 406 [ N(USE_TRANSP) N(ESP_TFC_PAD_N) SA No TSi TSr ]
15[NET] &lt;con2|352&gt; sending packet: from x.x.x.x[500] to y.y.y.y[500] (224 bytes)
16[NET] &lt;con2|352&gt; received packet: from y.y.y.y[500] to x.x.x.x[500] (80 bytes)
16[ENC] &lt;con2|352&gt; parsed CREATE_CHILD_SA response 406 [ N(TS_UNACCEPT) ]
16[IKE] &lt;con2|352&gt; received TS_UNACCEPTABLE notify, no CHILD_SA built
16[IKE] &lt;con2|352&gt; failed to establish CHILD_SA, keeping IKE_SA
16[CHD] &lt;con2|352&gt; CHILD_SA con2{25048} state change: CREATED =&gt; DESTROYING
</code></pre>
<p dir="auto">As far as I understand this means that traffic selector does not match. But in transport mode no traffic selectors can be specified.<br />
What need to be fixed?<br />
Thanks in advance.</p>
]]></description><link>https://forum.netgate.com/topic/177535/gre-ipsec-transport-mode-with-cisco-router</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 05:28:34 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/177535.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 03 Feb 2023 14:15:05 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to GRE+IPsec transport mode with Cisco router on Fri, 03 Feb 2023 18:45:48 GMT]]></title><description><![CDATA[<p dir="auto">Unfortunately I don't have access to Cisco.</p>
]]></description><link>https://forum.netgate.com/post/1084015</link><guid isPermaLink="true">https://forum.netgate.com/post/1084015</guid><dc:creator><![CDATA[ps0]]></dc:creator><pubDate>Fri, 03 Feb 2023 18:45:48 GMT</pubDate></item><item><title><![CDATA[Reply to GRE+IPsec transport mode with Cisco router on Fri, 03 Feb 2023 16:46:54 GMT]]></title><description><![CDATA[<p dir="auto">You might need to check the logs on the Cisco and see exactly what it's rejecting. All pfSense can see is that Cisco didn't like it, not why.</p>
]]></description><link>https://forum.netgate.com/post/1083982</link><guid isPermaLink="true">https://forum.netgate.com/post/1083982</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Fri, 03 Feb 2023 16:46:54 GMT</pubDate></item></channel></rss>