Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSEC with IKEv2 and PSK

    Scheduled Pinned Locked Moved IPsec
    5 Posts 4 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      DrMxxxxx
      last edited by

      Hi All,

      I think I'm blind or do not understand how this is working.

      I want to establish a VPN Tunnel between an ASA an my pfsense and I want to use IKEv2. Now I got the configuration data incl. the two (local and remote) Passwords. The ASA is correctly configured and ready to go.

      But, when I now want to configure the IPSEC Tunnel on my pfsense, then I miss the field for TWO Passwords. I can only configure one PSK.

      I tried both Passwords in the PSK field in the IPSEC configuration, but I got an AUTH_FAIL in the Logs. Then I tried to configure the both Passwords in the Preshared Key with the IP Addresses as Identifier. But again I'm getting AUTH_FAIL in the Logs.

      Where do I have to configured the two Passwords is my question!

      Many thanks in advance!

      Kind Regards,
      DrMxxxxx

      1 Reply Last reply Reply Quote 0
      • W
        wickeren
        last edited by

        As far as I'm aware of, PSK is just ONE password, shared between both sites. There is no such thing as a local and remote password

        1 Reply Last reply Reply Quote 0
        • L
          laped
          last edited by

          Think it's the mutual psk + xauth authentication option that you have to use for that. Also only IKEv1 i think.

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            The ASA lets you configure a different local and remote PSK with IKEv2, we use the same for both like most everything else does. Configure both the same on the ASA.

            1 Reply Last reply Reply Quote 0
            • D
              DrMxxxxx
              last edited by

              Hi All,

              thanks for the answers. We decided to take IKEv1 … Now it is working. :)

              Regards,
              M

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.