OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 18.1 Legacy Series »
  • [SOLVED] IPSec Bug?
« previous next »
  • Print
Pages: [1]

Author Topic: [SOLVED] IPSec Bug?  (Read 5737 times)

GaardenZwerch

  • Full Member
  • ***
  • Posts: 102
  • Karma: 2
    • View Profile
[SOLVED] IPSec Bug?
« on: July 17, 2018, 04:16:28 pm »
Hi,

I have discovered weird behaviour with IPSec:
one local network needs to access two different networks behind the same remove IPSec gateway.
So I figured I create one Phase-1 entry and attach two phase-2 entries (one for each remote net) to it.
It won't work.

Desperate, I went ahead and created two exactly identical Phase-1 entries (same IPs, same shared secret) an attached one Phase-2 to each of them. Works like a charm. Is this expected behaviour?

See attached screenshots for clarity

« Last Edit: July 19, 2018, 09:43:30 am by franco »
Logged

camouflageX

  • Newbie
  • *
  • Posts: 15
  • Karma: 1
    • View Profile
Re: IPSec Bug?
« Reply #1 on: July 18, 2018, 07:16:45 am »
Hello,

we use multiple phase 2 entries and it works fine. What IPsec software is on the other side? Do you have any log entries when it tries to establish the connection?
Logged

GaardenZwerch

  • Full Member
  • ***
  • Posts: 102
  • Karma: 2
    • View Profile
Re: IPSec Bug?
« Reply #2 on: July 18, 2018, 07:34:13 am »
Hi,

the other end is CISCO.

here's the error I got when doing ipsec up conXX on the command line.

IKE_SA con2[21] established between [deleted IPs]
scheduling reauthentication in 2696s
maximum IKE_SA lifetime 3236s
received TS_UNACCEPTABLE notify, no CHILD_SA built
failed to establish CHILD_SA, keeping IKE_SA
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13936
  • Karma: 1208
    • View Profile
Re: IPSec Bug?
« Reply #3 on: July 19, 2018, 12:14:20 am »
Can you try the phase 1 Tunnel Isolation mode? It should work... it's the same as adding multiple phase 1 with the same config with a single phase 2 on top. My FortiGate devices need this, otherwise they won't route more than one phase 2.


Cheers,
Franco
Logged

GaardenZwerch

  • Full Member
  • ***
  • Posts: 102
  • Karma: 2
    • View Profile
Re: IPSec Bug?
« Reply #4 on: July 19, 2018, 07:35:21 am »
Thanks Franco,
that's it.
I will ask what exactly the other side runs, maybe you want to extend the documentation of the option.

Thanks a lot,

Frank
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6332
  • Karma: 435
    • View Profile
Re: IPSec Bug?
« Reply #5 on: July 19, 2018, 08:00:32 am »
Can you clarify what exactly Cisco modell an version?
I run many VPNs with IOS routers very fine ..
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

GaardenZwerch

  • Full Member
  • ***
  • Posts: 102
  • Karma: 2
    • View Profile
Re: IPSec Bug?
« Reply #6 on: July 19, 2018, 08:39:58 am »
Hi again,
for your info;
remote is a Cisco 3925 (with encryption board) running IOS 15.4.3M8

I consider my problem as solved.

Frank
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6332
  • Karma: 435
    • View Profile
Re: IPSec Bug?
« Reply #7 on: July 19, 2018, 09:12:31 am »
Thanks!

I use the C886VA with the same IOS and it's working with multiple P2's without Tunnel Isolation, but good to know when there came problems in future.
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 18.1 Legacy Series »
  • [SOLVED] IPSec Bug?
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2