OPNsense Forum

English Forums => Virtual private networks => Topic started by: Andi.K on April 15, 2025, 09:29:38 AM

Title: IPSEC Interface
Post by: Andi.K on April 15, 2025, 09:29:38 AM
Hello everyone,

I have connected two current Sense with an IPSEC (new version) via S2S VPN. So far everything is ok.

One of the sites has Multi WAN. But the backup WAN is not usable for the VPN.

In the legacy version I was able to select the interface for the tunnel. This option is missing in the new version. How can I bind the tunnel to a WAN interface?

Thanks, Andi
Title: Re: IPSEC Interface
Post by: Monviech (Cedrik) on April 15, 2025, 11:56:52 AM
Hello,

you bind the tunnel to an interface by setting the IP address in the local addresses field in the connection dialog.
Title: Re: IPSEC Interface
Post by: Andi.K on April 15, 2025, 01:57:47 PM
That's what I would have expected, but it doesn't seem to be the case.

I can see the false WAN IP in the log on the other side with the message "no IKE config found for ...... NO_PROPOSAL_CHOSEN"

Additional question: Where did the settings for:
"Connection Method" / Respond only etc.

Thank you for your help

Andi
Title: Re: IPSEC Interface
Post by: Monviech (Cedrik) on April 15, 2025, 02:18:15 PM
Hmm okay interesting, I would have assumed that if the WAN IP is not available the traffic will not be sent out.

The respond only is in the child now, you can set the start action to none for example.
Title: Re: IPSEC Interface
Post by: Andi.K on April 15, 2025, 03:16:54 PM
Thanks for the tip with the child

I also find the interface thing strange, but I don't know what I could have done wrong. An explicit setting for the interface would be useful, I use it often.
Title: Re: IPSEC Interface
Post by: dcol on April 15, 2025, 04:58:51 PM
What would also be useful is less conflicting and confusing instructions on the Deciso site.
Problem is as OPNsense makes changes, these changes are not reflected in the guide.