2 IPsec via two WAN connections, one is stable, the other does not rekey sometim



  • Hi,

    i have craeted two IPsec/GRE connections between two PFsense 2.2.3.
    the main connections has the official IP on the CARP Interface to the other officical CARP IP on the other side.
    Authentication is done via PSK. This connection with IPsec transport mode is stable.

    the second connections get's connected with a separate PPPoe router in front and connects  to the same pfsense above, where this is also setup behind nat. In the testsetup the IPs are fixed, but when going production i could change from time to time on one side.
    Authentication is done with X509 certificates over this connection and the tunnel is working with IPsec tunnel mode (cause i want the Phase2 going between the two inofficial IPs.

    The problem with this tunnel is, sometimes there is no rekeying and on status/ipsec there is now P2 setup. P1 is there, but the tunnel itself is missing.

    How can i overcome this stability problem?
    Thomas



  • What do the IPsec logs show?



  • Hi cmb,

    thanks i have to restart the system and then wait for the error.

    thank you
    Thomas