VPN initiating from incorrect IP



  • I'm building an IPSEC VPN and I have set the interface to be a CARP address on my pfsense box (1.1.1.200).  However the device on the other side is seeing packets from the physical interface (1.1.1.201) of pfsense instead of the carp address.  I do a tcpdump on pfsense and it confirms that it's sending from .201 instead of .200.  Any ideas?

    Some additional info….I have about 10 VPNs.  All set to use .200.  Eight of the VPNs are properly established using .200, but the most recent two I've built are only using .201 and no matter what I do I can't get it to use .200.


  • Rebel Alliance Developer Netgate

    Check your outbound NAT and make sure you don't have a rule that might be catching the traffic (e.g. source = any)


Log in to reply