S2S IPSec With VTI Questions
-
Question arrising from an odd situation. I have three sites, two of them with 2 HA pfSense. One of the sites is the hub for the other two, and the hub does have two firewalls. For a few years I have a S2S between all the firewalls in a matrix fashion using VTI, and all has worked, with each VTI pair being it's own /30. For some reason some of the remote VTI's on the subnet now longer seem to be pingable, can't figure out why.
My question is, do I really need to have seperate /30's for each VTI pair or can I use a large /24 for ALL VTIs and make life a little simpler? Mocking everything up in GNS3 shows that it works, but not sure what the real world ramification of this would be. Thinking about just adding a new P2 to each connection and then removing the old P2, so that pairs that are working don't die suddenly.