<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPsec error connection after upgrading one site to 8.2.1]]></title><description><![CDATA[<p dir="auto">Hi<br />
We installed a new pfsense with 2.8.1 at a remote site and tried to establish an IPsec tunnel (P1) from another site which ran on 2.7.2<br />
We were not able to establish the connection, always got error message like the ones below.<br />
We have had a IPsec connection working between 2 sites running on 2.7.2<br />
After a while of trying out and checking we decided to upgrade one of the machines to 2.8.1<br />
Result: Now the formerly working IPsec connection can't be established showing the same errors.<br />
So my best guess is that there is a change of behaviour with 2.8.2. Unfortunately there is no easy way to rollback the machine and we have to get that going again. It doesn't seem to make much sense to upgrade the machine still running on 2.7.2<br />
since nothing works on 2.8.1<br />
If someone has an idea any help is very much appreciated!<br />
Thx</p>
<p dir="auto">Jul 17 17:33:59 	charon 	47965 	10[NET] &lt;82&gt; received packet: from 83.xx.xxx.xx[61884] to 192.168.1.122[500] (720 bytes)<br />
Jul 17 17:33:59 	charon 	47965 	10[ENC] &lt;82&gt; parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(HASH_ALG) N(REDIR_SUP) ]<br />
Jul 17 17:33:59 	charon 	47965 	10[CFG] &lt;82&gt; looking for an IKEv2 config for 192.168.1.122...83.xx.xxx.xx<br />
Jul 17 17:33:59 	charon 	47965 	10[CFG] &lt;82&gt; candidate: 192.168.1.122...83.xx.xxx.xx, prio 3100<br />
Jul 17 17:33:59 	charon 	47965 	10[CFG] &lt;82&gt; found matching ike config: 192.168.1.122...83.xx.xxx.xx with prio 3100<br />
Jul 17 17:33:59 	charon 	47965 	10[IKE] &lt;82&gt; local endpoint changed from 0.0.0.0[500] to 192.168.1.122[500]<br />
Jul 17 17:33:59 	charon 	47965 	10[IKE] &lt;82&gt; remote endpoint changed from 0.0.0.0 to 83.xx.xxx.xx[61884]<br />
Jul 17 17:33:59 	charon 	47965 	10[IKE] &lt;82&gt; 83.xx.xxx.xx is initiating an IKE_SA<br />
Jul 17 17:33:59 	charon 	47965 	10[IKE] &lt;82&gt; IKE_SA (unnamed)[82] state change: CREATED =&gt; CONNECTING<br />
Jul 17 17:33:59 	charon 	47965 	10[CFG] &lt;82&gt; selecting proposal:<br />
Jul 17 17:33:59 	charon 	47965 	10[CFG] &lt;82&gt; proposal matches<br />
Jul 17 17:33:59 	charon 	47965 	10[CFG] &lt;82&gt; received proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_4096<br />
Jul 17 17:33:59 	charon 	47965 	10[CFG] &lt;82&gt; configured proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_4096<br />
Jul 17 17:33:59 	charon 	47965 	10[CFG] &lt;82&gt; selected proposal: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_4096<br />
Jul 17 17:33:59 	charon 	47965 	10[CFG] &lt;82&gt; received supported signature hash algorithms: sha256 sha384 sha512 identity<br />
Jul 17 17:33:59 	charon 	47965 	10[IKE] &lt;82&gt; local host is behind NAT, sending keep alives<br />
Jul 17 17:33:59 	charon 	47965 	10[IKE] &lt;82&gt; remote host is behind NAT<br />
Jul 17 17:33:59 	charon 	47965 	10[CFG] &lt;82&gt; sending supported signature hash algorithms: sha256 sha384 sha512 identity<br />
Jul 17 17:33:59 	charon 	47965 	10[ENC] &lt;82&gt; generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(HASH_ALG) N(CHDLESS_SUP) N(MULT_AUTH) ]<br />
Jul 17 17:33:59 	charon 	47965 	10[NET] &lt;82&gt; sending packet: from 192.168.1.122[500] to 83.xx.xxx.xx[61884] (728 bytes)<br />
Jul 17 17:33:59 	charon 	47965 	10[NET] &lt;82&gt; received packet: from 83.xx.xxx.xx[4500] to 192.168.1.122[4500] (272 bytes)<br />
Jul 17 17:33:59 	charon 	47965 	10[ENC] &lt;82&gt; parsed IKE_AUTH request 1 [ IDi AUTH N(ESP_TFC_PAD_N) SA TSi TSr N(MULT_AUTH) N(EAP_ONLY) N(MSG_ID_SYN_SUP) ]<br />
Jul 17 17:33:59 	charon 	47965 	10[IKE] &lt;82&gt; local endpoint changed from 192.168.1.122[500] to 192.168.1.122[4500]<br />
Jul 17 17:33:59 	charon 	47965 	10[IKE] &lt;82&gt; remote endpoint changed from 83.xx.xxx.xx[61884] to 83.xx.xxx.xx[4500]<br />
Jul 17 17:33:59 	charon 	47965 	10[CFG] &lt;82&gt; looking for peer configs matching 192.168.1.122[%any]...83.xx.xxx.xx[192.168.200.103]<br />
Jul 17 17:33:59 	charon 	47965 	10[CFG] &lt;82&gt; no matching peer config found<br />
Jul 17 17:33:59 	charon 	47965 	10[IKE] &lt;82&gt; received ESP_TFC_PADDING_NOT_SUPPORTED, not using ESPv3 TFC padding<br />
Jul 17 17:33:59 	charon 	47965 	10[ENC] &lt;82&gt; generating IKE_AUTH response 1 [ N(AUTH_FAILED) ]<br />
Jul 17 17:33:59 	charon 	47965 	10[NET] &lt;82&gt; sending packet: from 192.168.1.122[4500] to 83.xx.xxx.xx[4500] (80 bytes)<br />
Jul 17 17:33:59 	charon 	47965 	10[IKE] &lt;82&gt; IKE_SA (unnamed)[82] state change: CONNECTING =&gt; DESTROYING</p>
]]></description><link>https://forum.netgate.com/topic/200969/ipsec-error-connection-after-upgrading-one-site-to-8.2.1</link><generator>RSS for Node</generator><lastBuildDate>Sun, 16 Aug 2026 19:55:47 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/200969.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 17 Jul 2026 15:49:33 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IPsec error connection after upgrading one site to 8.2.1 on Sun, 02 Aug 2026 19:41:56 GMT]]></title><description><![CDATA[<p dir="auto">You should just set the identifier to something specific but valid. So I'd use FQDN, it doesn't change with actual IP address used. It only needs to match at each end.</p>
]]></description><link>https://forum.netgate.com/post/1245966</link><guid isPermaLink="true">https://forum.netgate.com/post/1245966</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Sun, 02 Aug 2026 19:41:56 GMT</pubDate></item><item><title><![CDATA[Reply to IPsec error connection after upgrading one site to 8.2.1 on Sun, 02 Aug 2026 14:31:24 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/stephenw10">@<bdi>stephenw10</bdi></a> Thanks for answering, I downgraded both FWs back to 2.7.2 (having a steep learning curve) changed "Peer identifier" entry in P1 to any and it works well. I tried that with 2.8.1 as well with no luck.<br />
It really looks like a "2.8.1 thing", I don't dare to upgrade for the time being.</p>
]]></description><link>https://forum.netgate.com/post/1245956</link><guid isPermaLink="true">https://forum.netgate.com/post/1245956</guid><dc:creator><![CDATA[fme]]></dc:creator><pubDate>Sun, 02 Aug 2026 14:31:24 GMT</pubDate></item><item><title><![CDATA[Reply to IPsec error connection after upgrading one site to 8.2.1 on Sat, 25 Jul 2026 13:17:53 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/fme">@<bdi>fme</bdi></a> said in <a href="/post/1245334">IPsec error connection after upgrading one site to 8.2.1</a>:</p>
<blockquote>
<p dir="auto">Jul 17 17:33:59 charon 47965 10[CFG] &lt;82&gt; looking for peer configs matching 192.168.1.122[%any]...83.xx.xxx.xx[192.168.200.103]<br />
Jul 17 17:33:59 charon 47965 10[CFG] &lt;82&gt; no matching peer config found<br />
Jul 17 17:33:59 charon 47965 10[IKE] &lt;82&gt; received ESP_TFC_PADDING_NOT_SUPPORTED, not using ESPv3 TFC padding<br />
Jul 17 17:33:59 charon 47965 10[ENC] &lt;82&gt; generating IKE_AUTH response 1 [ N(AUTH_FAILED) ]</p>
</blockquote>
<p dir="auto">That looks like an identifier mismatch. The remote side is sending it's local IP as the Identifier because it's behind NAT (presumably) and the local side doesn't have a P1 that matches.</p>
]]></description><link>https://forum.netgate.com/post/1245645</link><guid isPermaLink="true">https://forum.netgate.com/post/1245645</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Sat, 25 Jul 2026 13:17:53 GMT</pubDate></item></channel></rss>