OPNsense Forum

Archive => 18.7 Legacy Series => Topic started by: sachaz on July 24, 2018, 01:05:26 am

Title: IPSec Phase 1 IPv4 Phase 2 IPv6
Post by: sachaz on July 24, 2018, 01:05:26 am
Hi,

I'm trying to do something like this:

ServerZZTop ----- FirewallA [OPNSense] o===(IPSEC)===o FirewallB [OpenBSD] ----- Internet

ServerZZTop have a public IPv4/6

Phase 1 Type: IPv4 IKE v1
Phase 2 Type:  ESP IPv4 tunnel
Phase 2 Type:  ESP IPv6 tunnel

Yes I got I phase 2 for an IPv4 tunnel AND another one for an IPv6 tunnel, Strongswan is suposed to work like this(https://www.strongswan.org/testing/testresults/ipv6/net2net-ip6-in-ip4-ikev1/).

1st problem is the following message when I try to modify my phase 1: "There is a Phase 2 using IPv6, you cannot use IPv4".

When I mount the tunnel:

I'm stucked to make the IPv6 Phase2 and I don't understand why I have this message from OPNSense (my 1st problem)

Kind regards
Title: Re: IPSec Phase 1 IPv4 Phase 2 IPv6
Post by: sachaz on August 02, 2018, 09:30:24 am
All of this is fixed now: https://atelier.aquilenet.fr/projects/services/wiki/Librehosting