1
20.7 Legacy Series / Problem with multi phase2 ipsec vpn's
« on: August 25, 2020, 06:26:31 pm »
Since 20.1.9 where I have observed first time this, not sure that it does not start in 20.1.8 and up till 20.7.1 in all versions of opnsense I have seen that IPsec chooses last flow of phase2 to send all outgoing traffic, while incoming traffic is displays correctly for every flow.
tcpdump also shows that only one spi is chosen for all outgoing traffic which makes problem with some cisco routers.
Is there any settings that can make ipsec see flows like in 20.1.7 and previous versions?
Correctrion.
Problem is with manualy added spd entries.
I have found better described problem here:
https://github.com/opnsense/core/issues/2173
tcpdump also shows that only one spi is chosen for all outgoing traffic which makes problem with some cisco routers.
Is there any settings that can make ipsec see flows like in 20.1.7 and previous versions?
Correctrion.
Problem is with manualy added spd entries.
I have found better described problem here:
https://github.com/opnsense/core/issues/2173