IPSEC autoconnection - Manual?
-
Hello.
I setup IPSEC site 2 site between Pfsense CE 2.7.2 vs Pfsense Plus 24.03 shared key.
Following the instructions from the pfsense bible(Doc).
My fws are behind my ISP routers, I open the ports on both sides.
The tunnel is on, but I notice 1 behaviour:
-
To establish the tunnel I manually need to press connect P1 and P2 on the status ipsec and the tunnel goes live.
-
fI add on P2 keep alive, the IP of each pfsense IP, this way it connects automatically.
I was thinking that the tunnel will connected without intervention, like openvpn does.
This is normal or I miss something?
Any comment or tip is welcome.
Thanks in advaced.
-
-
The default behavior varies by type (policy-based vs route-based/VTI). For policy-based tunnels the tunnel will connect on demand by default, so it will wait for some traffic to try taking the tunnel before the tunnel is established. As you found, keep alive will nudge this to happen sooner.
Read through these parts of the docs:
-
@jimp Thanks master, I will.