OPNsense Forum

Archive => 23.1 Legacy Series => Topic started by: whatever on March 11, 2023, 09:27:28 PM

Title: IKEv2 IPSec EAP-TLS (RSA local) + (EAP-TLS remote) appears broken
Post by: whatever on March 11, 2023, 09:27:28 PM
Hello,

I'm transitioning over from pfSense to OPNsense and I've been "cloning" the pfSense box settings on OPNsense. Everything is working great except IPSec. I can't for the life of me get it working. I've checked the settings well over 100 times and they're correct. On pfSense it works perfectly. On OPNsense, when I try to connect a client it instantly disconnects. The strange thing is that I see no error messages at all in the IPSec logs - the client hits the server and the logs are full of "success" statements - no errors. And so I have no idea where to look to fix the issue. I've torn down the tunnel and started over more times than I can count. I also reinstalled OPNsense from scratch and reconfigured IPSec - same exact result. It was working prior to the update to 23.1_2. I'm now on 23.1_3 but that update didn't help.

Off the top of anyone's head do you have any ideas where I should look?

Here are screenshots of my config and logs:

[I removed the screenshots because they're pointless now - the settings are fine - see below]

Thanks
Title: Re: IKEv2 IPSec EAP-TLS (RSA local) + (EAP-TLS remote) appears broken
Post by: Flamez on March 11, 2023, 10:23:50 PM
I have also ran into this issue.  It was working before updating from 23.1_2. to 23.1_3.
Title: Re: IKEv2 IPSec EAP-TLS (RSA local) + (EAP-TLS remote) appears broken
Post by: whatever on March 12, 2023, 07:51:46 AM
So I reinstalled 23.1 and restored my config with those exact IPSec settings in and it just worked. Updated to 23.1.3 and after the reboot, IPSec is broken. So it would appear to be realted to the subsequent updates of OPNsense somehow. I'd be quite happy to stay on 23.1 but I can't install any packages. When I try it tells me that my installation is outdated and I need to update. Any way around this?
Title: Re: IKEv2 IPSec EAP-TLS (RSA local) + (EAP-TLS remote) appears broken
Post by: mimugmail on March 12, 2023, 09:51:08 AM
Can you raise a ticket in Github for this please?
Title: Re: IKEv2 IPSec EAP-TLS (RSA local) + (EAP-TLS remote) appears broken
Post by: whatever on March 12, 2023, 06:39:45 PM
Sure, in which section, "core"? (never opened a ticket before).
Title: Re: IKEv2 IPSec EAP-TLS (RSA local) + (EAP-TLS remote) appears broken
Post by: franco on March 12, 2023, 07:26:18 PM
Looks like it was reported via https://github.com/opnsense/core/issues/6415


Thanks,
Franco
Title: Re: IKEv2 IPSec EAP-TLS (RSA local) + (EAP-TLS remote) appears broken
Post by: whatever on March 12, 2023, 07:39:32 PM
That's me ;-)