IPSEC VPN AZURE VTI
-
Hello,
I have a problem communicating with the tunnel, the connection is established but nothing comes through.
IP-address: xx.xx.xx.xx
PSK: sdfsdfsdfsdf
Traffic selection: Route-based
IKE Protocol: IKEv2IKE Phase 1 parameters:
• Encryption: AES256
• Integrity/PRF: SHA256
• DH Group: 14IKE Phase 2 (IPSec) parameters:
• Encryption: AES256
• Integrity: SHA256
• PFS Group: None
• SA lifetime (kb): 102400000
• SA lifetime (sec): 27000Routed subnets:
• 10.192.0.0/21Do you have an idea ?
-
Have you read https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/routed-vti.html?
That doc suggests configuring a transit network (which could be a /30), and that the two endpoints of the transit network would be configured as ADDRESS rather than NETWORK in the P2.
You don't mention which version you're running, but if you are on 24.03, note this thread https://forum.netgate.com/topic/188214/vti-gateways-not-adding-static-routes-in-24-03/. There is a patch to address the issue of the necessary static routes not being added.
--Larry