Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec Tunnel working, but not for one of the P2 on site 3

    Scheduled Pinned Locked Moved IPsec
    1 Posts 1 Posters 149 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      ggorman
      last edited by

      One of our IPsec tunnels is not connecting correctly.
      Is working correctly from another site to site.

      Each site uses pfSense, CE, or Plus editions.

      Currently, the configuration of the works on site 2 to site 1

      Private network: 10.27.0.0/24

      Connecting through IPsec tunnel to Main site on private network
      10.24.0.0/22
      10.24.8.0/24
      10.24.28.0/22
      10.48.0.0/18
      fa4599a3-f35e-4c78-9e47-9eed193e4781-image.png

      Our 3rd site (P2 not working)

      Private network 10.28.0.0/24
      Connection through IPsec tunnel to Main site on private network.
      10.24.0.0/22
      10.24.8.0/24
      10.24.28.0/22

      9355524e-9b3f-4816-bc4b-719dad32c54a-image.png

      Same information for the P2 setup on both; however, on the 3rd site, it will not connect to the additional private network.

      Configuration of P2 for both sites is the following.

      Networks:
      Local Network: LAN subnet
      Nat: None
      Remote network: Network: 10.48.0.0/18

      Phase 2 Proposal: This is set up like other P2 connections.
      And is pointing to the correct P1

      Have a Static route setup as well on 2nd and 3rd site
      10.48.8.0/24 to LANGW on lan interface.

      Traceroute from site 3 shows, Not working site to site
      1 10.28.0.1 0.517 ms 0.244 ms 0.192 ms
      2 10.28.0.1 0.281 ms 0.270 ms 0.256 ms
      3 10.28.0.1 0.357 ms 0.342 ms 0.347 ms
      4 10.28.0.1 0.419 ms 0.413 ms 0.430 ms

      Traceroute from site 2 shows, Working site to site
      1 10.27.0.1 0.043 ms 0.009 ms 0.011 ms
      2 * * *
      3 10.48.8.11 5.741 ms 5.738 ms 5.741 ms

      I've gone through the guide for doing IPSec setup many times and setup is correct on both ends. However, I feel like I'm over looking something very simple.

      Thanks for any tips.

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.