|
I upgraded to 96.2 and ran the test again. I reloaded both
boxes and cleared the ipsec.log.
Looks like it has trouble binding to the addresses on
remote1. Nothing in the logs on central 1 make it look like the connection
is making it there.
Attached are the ipsec.log from remote1 and central1 (vip
master).
The only things changed is remote1's wan ip is changed to
77.77.77.x and the Central1 Wan/vip range is change to
99.99.99.x
Currently the setup is as follows. (Remote1 also has
another interface that has an ip but only used to link it to another
lan)
172.16.10.0/24 remote1 ------> VIP --/
Central 1\ -- VIP-- 172.16.0.0/24
\ Central 2/
Central 1 and 2 share VIP address via
carp.
IPSec is setup for mobile clients
Mode - Aggressive
Identifier FQDN - [EMAIL PROTECTED]
Encryption - 3DES
Hash - SHA1
DH Key Group - 2
Lifetime 60
Auth Method - Pre-Share Key
Phase 2
Protocol - ESP
Encryption - 3DES, Blowfish
Hash - Sha1
PFS - Off
Lifetime - 60
Remote 1 is setup as a tunnel
Interface - WAN
Local Sub - 172.16.10.0 /24
Remote Sub - 172.16.0.0 /24
Remote Gateway - VIP of Central 1 &
2
Mode - Aggressive
Identifier FQDN - [EMAIL PROTECTED]
Encryption - 3DES
Hash - SHA1
DH Key Group - 2
Lifetime 60
Auth Method - Pre-Share Key
(preshare key is entered)
Phase 2
Protocol - ESP
Encryption - 3DES, Blowfish
Hash - Sha1
PFS - Off
Lifetime - 60
All
devices have the same pre-shared keys / passwords are also the
same
As I
mentioned before I don't see anything in Status->IPSec->SPD where I did
see the policy in versions like 94.10
Thanks
John
From: Holger Bauer [mailto:[EMAIL PROTECTED] Sent: Tuesday, December 13, 2005 5:58 PM To: [email protected] Subject: AW: [pfSense Support] Re: IPSec Broken in 95.8 Embedded? could you give us a mockup what kind of ipsec you are using and how it is
set up? maybe even the ipsec config sections with removed secrets of both
endpoints? Also, like scott said already, logs from both sides would be
helpful. If you don't want to send it to the list send them offlist. I can try
to simulate your setup here in my lab.
Holger
|
gw-central1-ipsec.log
Description: gw-central1-ipsec.log
gw-remote1-ipsec.log
Description: gw-remote1-ipsec.log
--------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]
