Hi All
I feel like I'm going crazy here. I'm looking to setup an IPSEC S2S tunnel from an OPNsense firewall to potentially a number of other firewalls. I appear to be running the "new" UI for this and all the docs I can find talk about a legacy mode, and the documentation for legacy mode makes sense. It talks about Phase 1 and Phase 2, it talks about proposals, shared secrets, IKE and ESP and all the normal IPSEC things.
This new UI doesn't even have most of that. I can see you can select proposals when seeing up a new connection, but there appears to be no place to edit or add to the predefined ones. Lifetimes _may_ be under the advanced section of the connection but aren't called lifetimes, instead they are, I'm guessing, Re-auth time and Rekey time. No mention of PFS anywhere.
I get this might all just be trying to make it easier for beginner users, but wow does this not look like any IPSEC setup I've ever encountered (and I've been in networking for a couple of decades)
Am I on the right path here? Can we just not create our own proposals (not to mention what exactly _is_ the default proposal)? Is PFS supported anywhere?
This is about the most useful piece of docs I've found but there are... gaps
Thanks
PS. Sorry for the frustrated tone, but this is, well, frustrating :)
I feel like I'm going crazy here. I'm looking to setup an IPSEC S2S tunnel from an OPNsense firewall to potentially a number of other firewalls. I appear to be running the "new" UI for this and all the docs I can find talk about a legacy mode, and the documentation for legacy mode makes sense. It talks about Phase 1 and Phase 2, it talks about proposals, shared secrets, IKE and ESP and all the normal IPSEC things.
This new UI doesn't even have most of that. I can see you can select proposals when seeing up a new connection, but there appears to be no place to edit or add to the predefined ones. Lifetimes _may_ be under the advanced section of the connection but aren't called lifetimes, instead they are, I'm guessing, Re-auth time and Rekey time. No mention of PFS anywhere.
I get this might all just be trying to make it easier for beginner users, but wow does this not look like any IPSEC setup I've ever encountered (and I've been in networking for a couple of decades)
Am I on the right path here? Can we just not create our own proposals (not to mention what exactly _is_ the default proposal)? Is PFS supported anywhere?
This is about the most useful piece of docs I've found but there are... gaps
Thanks
PS. Sorry for the frustrated tone, but this is, well, frustrating :)
"