Ok, so no replies here :(
I searched a bit more, even on pfsense side, and it seems this is a limitation of the GUI for configuring such scenarios.
It's too bad, my old VPN (debian + strongswan) was configured this way and it was pretty straight forward.
I guess maybe the solution is to try to configure ipsec.conf manually? the issue is that eventually It will get replaced by the OPNsense GUI / services..
I searched a bit more, even on pfsense side, and it seems this is a limitation of the GUI for configuring such scenarios.
It's too bad, my old VPN (debian + strongswan) was configured this way and it was pretty straight forward.
I guess maybe the solution is to try to configure ipsec.conf manually? the issue is that eventually It will get replaced by the OPNsense GUI / services..