Quote from: nero355 on August 08, 2026, 01:36:51 PMThere has been a lot of IPSec talk lately because of some issues and there is also the fact that there are both a Legacy and a Current way to set things up IIRC so you need to figure all that stuff out first before you start !!
Unfortunately, I see no way to activate any form of "legacy" settings. All attempts to google this yield references to a page in OpnSense which apparently no longer exists, and a few results indicate the functionality was folded into the Connections page. However, on the Connections page, although there is a AES256-SHA1 setting in the drop-down, there's no way to select DH2 (which I believe translates into modp1024). Thus when I attempt to connect, I get a NO_PROPOSAL error.
I really, really, really do not want to have to regress to pfSense to resolve this. I've asked the client to upgrade their IPSEC hardware but that is going to take time for approvals and what not.
"