Unfortunately, the remote node A has a dynamic IP, otherwise we'd just be sticking with IKEv2. So we need aggressive mode to function.
EDIT: Is it possible to use IKEv2 with a dynamic IP on one side just by leaving the remote address in OPNsense's IPsec setup blank so it matches to any? I'm testing now and it seems like it works. Staying connected with a dynamic IP is the issue I am chiefly attempting to resolve, so as long as that works I'm happy to abandon aggressive mode.
EDIT: Is it possible to use IKEv2 with a dynamic IP on one side just by leaving the remote address in OPNsense's IPsec setup blank so it matches to any? I'm testing now and it seems like it works. Staying connected with a dynamic IP is the issue I am chiefly attempting to resolve, so as long as that works I'm happy to abandon aggressive mode.
"