Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec VTI with Dynamic Peer

    IPsec
    2
    2
    552
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      packetsar
      last edited by

      I'm setting up a VTI-IPSec tunnel between PFSense-A which has a static public IP, and PFSense-B which is behind a NAT (and the NAT has a dynamic IP).

      So PFSense-B has it's phase-1 settings using 0.0.0.0 as the Remote Gateway, uses "Any" for the Peer identifier, and is set to Responder Only for the Child SA Start Action

      If I use the above settings and create a phase-2 VTI, the tunnels will come up, the ipsec interface will show online, and routes will install into the routing table on both sides, but PFSense-A (the one with the dynamic peer configured) will never send any traffic over out its ipsec interface. Both sides show packets moving one way, and both agree none ever go the other way.

      If I create a regular non-VTI phase-2, everything works as expected.

      If I use dynamic DNS so PFSense-A and use a DNS name as its neighbor, everything works fine.

      Is this a limitation for VTIs on PFSense? Or did I hit a bug?

      PFSense-A Version: 2.6.0
      PFSense B Version: 23.05.1

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        That is expected and noted in the GUI:

        c93e825d-26f0-4859-99eb-5d883a0f76d3-image.png

        There is also more detail in the docs:

        https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/configure-p1.html#ike-endpoint-configuration

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 1
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.