Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    IpSec VPN and CARP IP

    IPsec
    3
    9
    2899
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Speck last edited by

      Hi,

      I'm trying to configure an IpSec tunnel between two PfSense firewall both version
      1.0.1
      built on Sun Oct 29 01:07:16 UTC 2006

      One one side PfSense WAN has a static ip address:

      xx.xx.xx.210

      and CARP IP til xx.xx.xx.222

      When I try to create a tunnel, I can only select which interface to listen to (WAN, DMZ, LAN) but how can I specify which IP to use?

      On the WAN static IP I forward IpSec port to a Win2003 server. So i need to specify one of the CARP IP as interface to listen to (the other side will use this ip as remote gateway)

      Is this possible?

      Thanks in advance,

      Speck

      1 Reply Last reply Reply Quote 0
      • S
        Speck last edited by

        Another problem I found…

        on the other PfSense when i try to start IpSec I get an error in racoon.conf line 2

        listen {
        isakmp  [500];

        }

        i found this in the file.

        This pfsense has a WAN with a static private IP 192.168.xx.xx and four VirtuaIp public configured.

        i tried to modify the file this way:

        listen {
        isakmp xx.xx.xx.149 [500];

        }

        but when i restart racoon it is overwritten with the old vesion.

        Thanks,
        Speck

        1 Reply Last reply Reply Quote 0
        • H
          hoba last edited by

          Hint: VPN>ipsec, failover ipsec tab

          1 Reply Last reply Reply Quote 0
          • S
            Speck last edited by

            Can I use FailOver Ipsec even if the vpn won't actually be a failover connection?

            I'll try this way, thanks

            1 Reply Last reply Reply Quote 0
            • S
              Speck last edited by

              What about the error in racoon.conf line 2? any hint  ???

              thanks

              1 Reply Last reply Reply Quote 0
              • S
                sullrich last edited by

                Thats fixed in a recent snapshot.

                1 Reply Last reply Reply Quote 0
                • S
                  Speck last edited by

                  latest snapshot is stable enough for production enviroinment?

                  The version I'm using now (1.0.1) is working great and very stable  ;D

                  Thanks in advance,
                  Speck

                  1 Reply Last reply Reply Quote 0
                  • H
                    hoba last edited by

                    We consider the releng1 snapshots as pretty stable. Only usability updates and bugfixes go into this branch. It's not like we are reinventing a new system here. Thet's what the head code tree is for. However, backing up your config before you upgrade won't hurt.

                    1 Reply Last reply Reply Quote 0
                    • S
                      Speck last edited by

                      Ok, thanks  ;D

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post