• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Multiple IPsec tunnels to the same Gateway

Scheduled Pinned Locked Moved IPsec
5 Posts 3 Posters 4.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    tchilders
    last edited by Jun 24, 2011, 9:35 PM

    I want to replace a Linksys RV016 with pfSense 2.0.  There are 5 IPsec tunnels supported by the Linksys to the same gateway, different subnets.  Actually, we are not allowed to connect to the subnets but only to specific IPs within their subnets (192.168.101.40, 192.168.102.40, 192.168.103.40, etc…..).  The Linksys supports this, no other appliance does that I know of, and I thought pfSense 2.0 would.
    When I try to set up the second tunnel I getting the error: "The remote gateway is already used by phase 1, 'description/name'".

    Is there a way to do this?

    1 Reply Last reply Reply Quote 0
    • S
      spiritbreaker
      last edited by Jun 27, 2011, 3:11 PM

      Hi,

      what u wanna do? What Device is on Remotesite?

      There are 5 IPsec tunnels supported by the Linksys to the same gateway, different subnets

      ??? PfSense supports many^^ tunnels to same gateway, depends on ur hardware. U can provide multible phase 2 entries.

      Actually, we are not allowed to connect to the subnets but only to specific IPs within their subnets (192.168.101.40, 192.168.102.40, 192.168.103.40, etc…..).

      U can write it like this: 192.168.101.40/255.255.255.255 ;) u can use it as Remotesubnet. BUT ist important to know whats defined on Remotesite!

      cya

      Pfsense running at 11 Locations
      -mobile OPENVPN and IPSEC
      -multiwan failover
      -filtering proxy(squidguard) in bridgemode with ntop monitoring

      1 Reply Last reply Reply Quote 0
      • T
        tchilders
        last edited by Jun 27, 2011, 7:24 PM

        The device at the remote site is either Linksys or Cisco, I'm not sure.  They have an MPLS system connecting a home office and 6 satellite facilities.  We connect to their central gateway and specify an IP address for each tunnel (i.e. Tunnel#1= GW 97.67.xx.xxx, IP 192.168.101.40).
        In setting up pfSense IPsec tunnel, the GW and Preshared Key are in Phase 1, then the local and remote IPs are in Phase 2.
        In the Linksys we have a different Preshared Key for each tunnel (plus different local IP's)…. if they are all the same, maybe we could use one phase 1, and multiple phase 2's?

        Thanks!
        TC

        1 Reply Last reply Reply Quote 0
        • C
          cmb
          last edited by Jun 27, 2011, 11:41 PM

          You only need one phase 1 and multiple phase 2s.

          1 Reply Last reply Reply Quote 0
          • T
            tchilders
            last edited by Jun 28, 2011, 3:08 PM

            Got it!
            ;D
            Thanks!

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received