<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[First timer&#x2F;newbie IPSec VPN….]]></title><description><![CDATA[<p dir="auto">I followed http://doc.pfsense.org/index.php/VPN_Capability_IPSec and have this all setup…. But when I go to the overview section...it's blank! I only have the tunnel I created in the SPD section.</p>
<p dir="auto">Am I missing something here?<br />
Is there more to it?</p>
<p dir="auto">What is the difference between SAD and SPD anyways...?</p>
<p dir="auto">Thanks!</p>
]]></description><link>https://forum.netgate.com/topic/8798/first-timer-newbie-ipsec-vpn</link><generator>RSS for Node</generator><lastBuildDate>Wed, 10 Jun 2026 11:59:19 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/8798.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 07 May 2008 23:49:40 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Fri, 23 May 2008 18:50:19 GMT]]></title><description><![CDATA[<p dir="auto">Cool!</p>
<p dir="auto">Thanks!</p>
]]></description><link>https://forum.netgate.com/post/174362</link><guid isPermaLink="true">https://forum.netgate.com/post/174362</guid><dc:creator><![CDATA[NoDoze]]></dc:creator><pubDate>Fri, 23 May 2008 18:50:19 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Fri, 23 May 2008 18:34:17 GMT]]></title><description><![CDATA[<p dir="auto">mobile client ipsec issue in 1.2 –&gt; in 1.21 that is fixed</p>
]]></description><link>https://forum.netgate.com/post/174359</link><guid isPermaLink="true">https://forum.netgate.com/post/174359</guid><dc:creator><![CDATA[heiko]]></dc:creator><pubDate>Fri, 23 May 2008 18:34:17 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Fri, 23 May 2008 17:08:29 GMT]]></title><description><![CDATA[<p dir="auto">WOOT! 'bout half an hour later we have CONNECTION! YES!<br />
Thank you! Thank you! Thank you!</p>
<p dir="auto">…All I did was just let it sit idle... the error log cleared out....I pinged, and then the logs showed CONNECTION ESTABLISHED!</p>
<p dir="auto">YES!</p>
<p dir="auto">So...why does it take so long for it to connect....?</p>
<p dir="auto">Thanks for the help!</p>
]]></description><link>https://forum.netgate.com/post/174353</link><guid isPermaLink="true">https://forum.netgate.com/post/174353</guid><dc:creator><![CDATA[NoDoze]]></dc:creator><pubDate>Fri, 23 May 2008 17:08:29 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Fri, 23 May 2008 15:27:26 GMT]]></title><description><![CDATA[<p dir="auto">Yup!…. both 1.2...</p>
<p dir="auto">Are you saying for the dynamic setup "mobile clients" needs to be enabled...?</p>
<p dir="auto">Well, I do have it enabled...on both sides....but it still isn't making the tunnel...</p>
<p dir="auto">Any other ideas...?</p>
]]></description><link>https://forum.netgate.com/post/174348</link><guid isPermaLink="true">https://forum.netgate.com/post/174348</guid><dc:creator><![CDATA[NoDoze]]></dc:creator><pubDate>Fri, 23 May 2008 15:27:26 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Fri, 23 May 2008 12:35:15 GMT]]></title><description><![CDATA[<p dir="auto">both on 1.2? / Unknown Gateway says that comes from a dynamic endpoint, nothing more</p>
<p dir="auto">I would work for example on the static side with the option "mobile clients enable" so the pf on the dynamic side<br />
works as it should. ;)</p>
]]></description><link>https://forum.netgate.com/post/174325</link><guid isPermaLink="true">https://forum.netgate.com/post/174325</guid><dc:creator><![CDATA[heiko]]></dc:creator><pubDate>Fri, 23 May 2008 12:35:15 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Thu, 22 May 2008 23:04:26 GMT]]></title><description><![CDATA[<p dir="auto">Ok, just to see if I could get it to work…I setup another IPsec tunnel, this time an internal one...<br />
...I still get the same errors in the logs:</p>
<blockquote>
<p dir="auto">May 22 22:58:49 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy already exists. anyway replace it: 192.168.25.0/24[0] 192.168.1.0/24[0] proto=any dir=out<br />
May 22 22:58:49 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy already exists. anyway replace it: 192.168.25.1/32[0] 192.168.25.0/24[0] proto=any dir=out<br />
May 22 22:58:49 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy already exists. anyway replace it: 192.168.1.0/24[0] 192.168.25.0/24[0] proto=any dir=in<br />
May 22 22:58:49 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy already exists. anyway replace it: 192.168.25.0/24[0] 192.168.25.1/32[0] proto=any dir=in</p>
</blockquote>
<p dir="auto">Can anyone make sense of this? (no pun intended)</p>
<p dir="auto">Thanks!</p>
]]></description><link>https://forum.netgate.com/post/174295</link><guid isPermaLink="true">https://forum.netgate.com/post/174295</guid><dc:creator><![CDATA[NoDoze]]></dc:creator><pubDate>Thu, 22 May 2008 23:04:26 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Thu, 22 May 2008 21:21:31 GMT]]></title><description><![CDATA[<p dir="auto">PF to PF both sides…<br />
the office is a static, the home a dynamic, but has never changed in 4 years.<br />
PF on both sides are setup static.</p>
]]></description><link>https://forum.netgate.com/post/174283</link><guid isPermaLink="true">https://forum.netgate.com/post/174283</guid><dc:creator><![CDATA[NoDoze]]></dc:creator><pubDate>Thu, 22 May 2008 21:21:31 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Thu, 22 May 2008 21:13:31 GMT]]></title><description><![CDATA[<p dir="auto">all ipsec endpoints are pfsense? if this so, are there are static or dynamic?</p>
]]></description><link>https://forum.netgate.com/post/174282</link><guid isPermaLink="true">https://forum.netgate.com/post/174282</guid><dc:creator><![CDATA[heiko]]></dc:creator><pubDate>Thu, 22 May 2008 21:13:31 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Thu, 22 May 2008 20:56:26 GMT]]></title><description><![CDATA[<p dir="auto">Ok, disregurad that last post… It went back to the way it was...</p>
<p dir="auto">Seams like PF keeps trying to make the connection but gets different responses?</p>
<p dir="auto">Anyways, I still can't get it to work...</p>
]]></description><link>https://forum.netgate.com/post/174281</link><guid isPermaLink="true">https://forum.netgate.com/post/174281</guid><dc:creator><![CDATA[NoDoze]]></dc:creator><pubDate>Thu, 22 May 2008 20:56:26 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Thu, 22 May 2008 19:37:21 GMT]]></title><description><![CDATA[<p dir="auto">I reduced the lifetime on both ends, and now get this error in the logs:</p>
<p dir="auto">On the home side:</p>
<pre><code>
May 22 12:26:10 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy already exists. anyway replace it: 192.168.2.5/32[0] 192.168.2.0/24[0] proto=any dir=out 
May 22 12:26:10 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy already exists. anyway replace it: 192.168.2.0/24[0] 192.168.2.5/32[0] proto=any dir=in 

</code></pre>
<p dir="auto">On the office side:</p>
<pre><code>
May 22 12:26:07 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy already exists. anyway replace it: 192.168.1.1/32[0] 192.168.1.0/24[0] proto=any dir=out 
May 22 12:26:07 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy already exists. anyway replace it: 192.168.1.0/24[0] 192.168.1.1/32[0] proto=any dir=in 

</code></pre>
<p dir="auto">So for some reason the liftime reduced the errors to one pair set on each side, whereas earlier is was two pair sets on each side.</p>
<p dir="auto">Still get nothing on the SAD and Overview. Just says "No IPsec security associations."<br />
Which leads me to beleive I'm leaving somthing out…?</p>
<p dir="auto">Help!</p>
<p dir="auto">Thanks!</p>
]]></description><link>https://forum.netgate.com/post/174273</link><guid isPermaLink="true">https://forum.netgate.com/post/174273</guid><dc:creator><![CDATA[NoDoze]]></dc:creator><pubDate>Thu, 22 May 2008 19:37:21 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Thu, 22 May 2008 17:36:09 GMT]]></title><description><![CDATA[<p dir="auto">OOooooohhhhh….! I always get those two mixed up...sorry...</p>
<p dir="auto">I made the changes 192.168.1.0 for the office and 192.168.2.0 for home, but still a no go...</p>
<p dir="auto">I'm getting these eror in the log:</p>
<blockquote>
<p dir="auto">May 22 10:32:53 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy already exists. anyway replace it: 192.168.1.0/24[0] 192.168.2.0/24[0] proto=any dir=out<br />
May 22 10:32:53 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy already exists. anyway replace it: 192.168.1.1/32[0] 192.168.1.0/24[0] proto=any dir=out<br />
May 22 10:32:53 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy already exists. anyway replace it: 192.168.2.0/24[0] 192.168.1.0/24[0] proto=any dir=in<br />
May 22 10:32:53 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy already exists. anyway replace it: 192.168.1.0/24[0] 192.168.1.1/32[0] proto=any dir=in</p>
</blockquote>
<p dir="auto">What does it mean?</p>
]]></description><link>https://forum.netgate.com/post/174265</link><guid isPermaLink="true">https://forum.netgate.com/post/174265</guid><dc:creator><![CDATA[NoDoze]]></dc:creator><pubDate>Thu, 22 May 2008 17:36:09 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Thu, 22 May 2008 07:23:31 GMT]]></title><description><![CDATA[<p dir="auto">Remote subnet  255.255.252.0 /  32 !!!</p>
<p dir="auto">The Remote subnet is for example 192.168.1.1, your lan subnet of the other side and not the "subnet mask" ;)</p>
]]></description><link>https://forum.netgate.com/post/174190</link><guid isPermaLink="true">https://forum.netgate.com/post/174190</guid><dc:creator><![CDATA[heiko]]></dc:creator><pubDate>Thu, 22 May 2008 07:23:31 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Wed, 21 May 2008 20:31:40 GMT]]></title><description><![CDATA[<p dir="auto">Uhmmm… Not sure what you're asking... I just copy/pasted from the pfsense VPN:IPsec window my settings...</p>
<p dir="auto">I basically followed the directions from: http://doc.pfsense.org/index.php/VPN_Capability_IPSec</p>
]]></description><link>https://forum.netgate.com/post/174180</link><guid isPermaLink="true">https://forum.netgate.com/post/174180</guid><dc:creator><![CDATA[NoDoze]]></dc:creator><pubDate>Wed, 21 May 2008 20:31:40 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Wed, 21 May 2008 20:04:55 GMT]]></title><description><![CDATA[<p dir="auto">what is Remote subnet  255.255.252.0 /  32 ??</p>
]]></description><link>https://forum.netgate.com/post/174179</link><guid isPermaLink="true">https://forum.netgate.com/post/174179</guid><dc:creator><![CDATA[heiko]]></dc:creator><pubDate>Wed, 21 May 2008 20:04:55 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Wed, 21 May 2008 17:55:29 GMT]]></title><description><![CDATA[<p dir="auto">Here are my settings… They are almost identical on both ends.</p>
<blockquote>
<p dir="auto">Office<br />
VPN: IPsec: Edit tunnel</p>
<p dir="auto">Mode Tunnel<br />
Interface  WAN<br />
Local subnet Type: LAN subnet<br />
Remote subnet  255.255.252.0 /  32<br />
Remote gateway  76.XX.XX.115<br />
Description  Home</p>
<p dir="auto">Phase 1 proposal (Authentication)<br />
Negotiation mode  aggressive<br />
My identifier  My IP address<br />
Encryption algorithm  Blowfish<br />
Hash algorithm  SHA1<br />
Must match the setting chosen on the remote side. <br />
DH key group  1<br />
Lifetime  28800<br />
Authentication method  Pre-shared key<br />
Pre-Shared Key  XXXXXXyadayadayadaXXXXX</p>
<p dir="auto">Phase 2 proposal (SA/Key Exchange)<br />
Protocol  ESP<br />
Encryption algorithms  Blowfish<br />
Hash algorithms  SHA1<br />
PFS key group  off<br />
Lifetime  28800</p>
</blockquote>
<blockquote>
<p dir="auto">Home<br />
VPN: IPsec: Edit tunnel</p>
<p dir="auto">Mode Tunnel<br />
Interface  WAN<br />
Local subnet Type: LAN subnet<br />
Remote subnet  255.255.255.224 /  32<br />
Remote gateway  71.XX.XX.162<br />
Description  Office</p>
<p dir="auto">Phase 1 proposal (Authentication)<br />
Negotiation mode  aggressive<br />
My identifier  My IP address<br />
Encryption algorithm  Blowfish<br />
Hash algorithm  SHA1<br />
Must match the setting chosen on the remote side. <br />
DH key group  1<br />
Lifetime  28800<br />
Authentication method  Pre-shared key<br />
Pre-Shared Key  XXXXXXyadayadayadaXXXXX</p>
<p dir="auto">Phase 2 proposal (SA/Key Exchange)<br />
Protocol  ESP<br />
Encryption algorithms  Blowfish<br />
Hash algorithms  SHA1<br />
PFS key group  off<br />
Lifetime  28800</p>
</blockquote>
]]></description><link>https://forum.netgate.com/post/174173</link><guid isPermaLink="true">https://forum.netgate.com/post/174173</guid><dc:creator><![CDATA[NoDoze]]></dc:creator><pubDate>Wed, 21 May 2008 17:55:29 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Tue, 13 May 2008 07:34:01 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nodoze">@<bdi>NoDoze</bdi></a>:</p>
<blockquote>
<p dir="auto">Am I missing something here?<br />
Is there more to it?</p>
<p dir="auto">Thanks!</p>
</blockquote>
<p dir="auto">Please give us more informations about your ipsec config</p>
]]></description><link>https://forum.netgate.com/post/173562</link><guid isPermaLink="true">https://forum.netgate.com/post/173562</guid><dc:creator><![CDATA[heiko]]></dc:creator><pubDate>Tue, 13 May 2008 07:34:01 GMT</pubDate></item><item><title><![CDATA[Reply to First timer&#x2F;newbie IPSec VPN…. on Tue, 13 May 2008 05:29:50 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">I followed http://doc.pfsense.org/index.php/VPN_Capability_IPSec and have this all setup…. But when I go to the overview section...it's blank! I only have the tunnel I created in the SPD section.</p>
</blockquote>
<p dir="auto">If you only have a SPD and not a SAD then you have no tunnel. In my experience Security Association Database (SAD) tells you that you are associated. If you have nothing in overview then i would say tunnel is not working</p>
<blockquote>
<p dir="auto">What is the difference between SAD and SPD anyways…?</p>
</blockquote>
<p dir="auto">Security Policy Database = SPD<br />
Security Association Database = SAD</p>
<blockquote>
<p dir="auto">Thanks!</p>
</blockquote>
]]></description><link>https://forum.netgate.com/post/173552</link><guid isPermaLink="true">https://forum.netgate.com/post/173552</guid><dc:creator><![CDATA[moffl]]></dc:creator><pubDate>Tue, 13 May 2008 05:29:50 GMT</pubDate></item></channel></rss>