Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Existing IPv4 IPSec tunnel – how to add IPv6

    IPv6
    2
    3
    1.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      miken32
      last edited by

      We have a Cisco ASA 5512 in our NOC and have a /48 from our provider. Remote offices have IPSec tunnels to the NOC with 192.168.x.x addressing. The remote offices do not have native IPv6 from their ISPs so I'd like to tunnel the IPv6 traffic back through the NOC.

      I've gotten as far as adding a second IPv6 phase 2 to my existing tunnel. LAN addressing is set up just fine. How do I tell pfSense to route the traffic through the tunnel though?

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        IIRC this probably won't work.

        First, it requires IKEv2 to be able to mix IPv4 and IPv6 on a single tunnel, but even then it may not function as expected. There are some issues with Cisco ASA and IKEv2 such as https://redmine.pfsense.org/issues/4704 that may also hold it back.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • M
          miken32
          last edited by

          Yes, I already worked around the multiple P2 issue with a config edit and both come up successfully.

          Tomorrow I'm going to try setting the network on the ASA side of the IPv6 P2 to ::/0 instead of the LAN address…

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.