<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPsec Mobile Clients]]></title><description><![CDATA[<p dir="auto">We've installed pfSense 2.0 RC1 in a test environment.  Working great so far!  We are thinking of replacing a Cisco ASA 5510, but have 1 small issue.  On the Cisco, we have multiple dial up client tunnels, each with a different group and PSK.  Based on the group and PSK, we assign users an address on a particular subnet, which allows us to control access to certain networks.  I was able to successfully configure 1 tunnel on pfSense and give access to multiple subnets, but I haven't found a way to create a second one that would use a different group, PSK and assign an address from a different subnet.  Is this possible on pfSense?  If not, I was hoping for some recommendations on what others are doing for similar situations.</p>
<p dir="auto">Thanks. -JP</p>
]]></description><link>https://forum.netgate.com/topic/32961/ipsec-mobile-clients</link><generator>RSS for Node</generator><lastBuildDate>Mon, 13 Apr 2026 08:53:57 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/32961.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 21 Apr 2011 17:24:41 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IPsec Mobile Clients on Wed, 27 Apr 2011 14:00:55 GMT]]></title><description><![CDATA[<p dir="auto">ok.. maybe that will work. but what is with my iOS devices? For them i have to use PSK + XAuth. And this isn´t possible with a second phase 1  :(</p>
<p dir="auto">i forgot to say that i´m using the latest 2.0 RC1 build.</p>
<p dir="auto">edit: ok, now i´m using only PSK´s +Xauth for the roadwarrior connections and it´s working like a charme with greenbow and iOS devices :)</p>
]]></description><link>https://forum.netgate.com/post/276403</link><guid isPermaLink="true">https://forum.netgate.com/post/276403</guid><dc:creator><![CDATA[pfsenseuser3]]></dc:creator><pubDate>Wed, 27 Apr 2011 14:00:55 GMT</pubDate></item><item><title><![CDATA[Reply to IPsec Mobile Clients on Wed, 27 Apr 2011 00:08:38 GMT]]></title><description><![CDATA[<p dir="auto">I believe when you set the certificate on the mobile IPsec p1 that is the <em>server side</em> certificate, not the client's certificate. I thought they just had to be from the same CA (the way OpenVPN works) and not match exactly. I may be incorrect, as I said I haven't used IPsec+certs before myself.</p>
]]></description><link>https://forum.netgate.com/post/276397</link><guid isPermaLink="true">https://forum.netgate.com/post/276397</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Wed, 27 Apr 2011 00:08:38 GMT</pubDate></item><item><title><![CDATA[Reply to IPsec Mobile Clients on Tue, 26 Apr 2011 23:42:16 GMT]]></title><description><![CDATA[<p dir="auto">each person should have a different certificate from the same CA.</p>
<blockquote>
<p dir="auto">you can do cert auth fine with multiple users so long as the certs are from the same CA</p>
</blockquote>
<p dir="auto">at the moment I have no pfsense box here (I am at home, here in austria it´s 1:40 am ;) ) but if I remember correctly, I have to set the certificate in phase 1. As I can only create one phase 1 for mobile clients I can´t select different certificates.</p>
<blockquote>
<p dir="auto">I use OpenVPN for all my mobile clients as it's much more flexible and less prone to errors and NAT issues on random remote networks.</p>
</blockquote>
<p dir="auto">The problem is, we are using the Greenbow VPN Client (IPSEC Client).. With the Ipcop it was no problem to create more than one roadwarrior connection, so we used that. Next step would be to integrate our iOS devices (iphones) and without jailbreak it is not possible to use OPENVPN on them.</p>
]]></description><link>https://forum.netgate.com/post/276396</link><guid isPermaLink="true">https://forum.netgate.com/post/276396</guid><dc:creator><![CDATA[pfsenseuser3]]></dc:creator><pubDate>Tue, 26 Apr 2011 23:42:16 GMT</pubDate></item><item><title><![CDATA[Reply to IPsec Mobile Clients on Tue, 26 Apr 2011 23:03:02 GMT]]></title><description><![CDATA[<p dir="auto">Each person should have a different certificate, or a different CA? As far as I remember, you can do cert auth fine with multiple users so long as the certs are from the same CA. I haven't done certs with IPsec though. I use OpenVPN for all my mobile clients as it's much more flexible and less prone to errors and NAT issues on random remote networks.</p>
]]></description><link>https://forum.netgate.com/post/276395</link><guid isPermaLink="true">https://forum.netgate.com/post/276395</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Tue, 26 Apr 2011 23:03:02 GMT</pubDate></item><item><title><![CDATA[Reply to IPsec Mobile Clients on Tue, 26 Apr 2011 22:56:23 GMT]]></title><description><![CDATA[<p dir="auto">hmmm and there is no solution for that? We have more than 5 mobile users and everyone should have his one certificate.. this is only possible with different phase 1.<br />
i´m currently in the test phase with pfsense and if it is not possible to add more than 1 mobile device i have to test another software.. at the moment i´m using ipcop.. but i think it´s outdated so i wanted to switch to another, more up to date software… now i´m thinking pfsense was the wrong way  :(</p>
]]></description><link>https://forum.netgate.com/post/276393</link><guid isPermaLink="true">https://forum.netgate.com/post/276393</guid><dc:creator><![CDATA[pfsenseuser3]]></dc:creator><pubDate>Tue, 26 Apr 2011 22:56:23 GMT</pubDate></item><item><title><![CDATA[Reply to IPsec Mobile Clients on Tue, 26 Apr 2011 14:42:44 GMT]]></title><description><![CDATA[<p dir="auto">If I remember right, the underlying software (racoon) can't have multiple definitions for the type of phase 1 required for mobile access. It's not just a limitation of the GUI.</p>
]]></description><link>https://forum.netgate.com/post/276317</link><guid isPermaLink="true">https://forum.netgate.com/post/276317</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Tue, 26 Apr 2011 14:42:44 GMT</pubDate></item><item><title><![CDATA[Reply to IPsec Mobile Clients on Tue, 26 Apr 2011 14:08:32 GMT]]></title><description><![CDATA[<p dir="auto">now i tried something tricky..</p>
<p dir="auto">https://192.168.1.1/vpn_ipsec_phase1.php?mobile=true</p>
<p dir="auto">with this link i tried to add a second phase 1 for another mobil client.. but as sone as i save the second phase 1 i also can´t connect with my first mobile device (vpn server timeout). When i delete the second phase 1 everything is working fine again.</p>
<p dir="auto">This seems like a big bug..</p>
]]></description><link>https://forum.netgate.com/post/276306</link><guid isPermaLink="true">https://forum.netgate.com/post/276306</guid><dc:creator><![CDATA[pfsenseuser3]]></dc:creator><pubDate>Tue, 26 Apr 2011 14:08:32 GMT</pubDate></item><item><title><![CDATA[Reply to IPsec Mobile Clients on Tue, 26 Apr 2011 08:57:01 GMT]]></title><description><![CDATA[<p dir="auto">i think we have the same problem. i´m also unable to create a second phase1 for a mobile client. i think it´s a bug.</p>
]]></description><link>https://forum.netgate.com/post/276270</link><guid isPermaLink="true">https://forum.netgate.com/post/276270</guid><dc:creator><![CDATA[pfsenseuser3]]></dc:creator><pubDate>Tue, 26 Apr 2011 08:57:01 GMT</pubDate></item></channel></rss>