Multiple Phase 2's network crosstalk


  • Hi,

    I've had a tunnel between two pfSense boxes running for a while with a single phase 2 tunnel between a 192.168.2.x/24 and a 192.168.3.x/24 subnet.

    I've now created a phase 2 entry between two LAB networks I set up on separate interfaces and assigned those new interfaces as the local subnet's on each side. However, the LAB subnets can talk with the original subnets on both sides and I can ping those LAB networks from the LAN networks. Why is this? This doesn't seem like desired behavior and it should be simple for me to create rules to block the traffic but I feel like these subnets shouldn't be talking to begin with.

    Any advice is appreciated!