Dears,
I have a question (and Issues -.-) with Route-Based IPsec setup.
First of all, I assume, that the Manual (https://docs.opnsense.org/manual/how-tos/ipsec-s2s-conn-route.html) is wrong at the Routes part: there it is stated, that on Site A the network address 10.0.2.0 (which additionally might be a typo as 10.2.0.0 was used) should be set... but 10.2.0.0 is the address of Site A and if one does... this kills the system (I tried in a third shot, as I am unable to get my VPN tunnel working)
For my issue (if anyone is willing to help): I've followed the instructions to 100% with one exception: my site B has no static public IP address... the rest has been kept as stated... (but I also have working policy-based Tunnels on Site A)
So as soon as I provide a Gateway, Site B tries to retransmit: "retransmit 1 of request with message ID 0" and Site A unregisters "05[CFG] vici client 2 unregistered for: list-conn" and finally disconnects... :((
A policy-based Tunnel has been created before as well, but I couldn't figure out how to fix the MTU issue... as soon as a package with a certain size hit the tunnel, the tunnel kept "connected", but no traffic flew through anymore... (tried all the normalization stuff :/)
therefore I tried to give the route-based tunnel a try... without luck as well -.-
Setup:
Site A, OPNsense 24.7.10_2-amd64 on FreeBSD 14.1-RELEASE-p6 (virtualized System) with a static public IP
Site B, OPNsense 24.7.10_2-amd64 on FreeBSD 14.1-RELEASE-p6 (Zima-Board) with a SIM-Card Router and non-static, non-public (incoming) IP / behind NAT
as stated... configured 1:1 like stated in the manual except the static IP parts
any help is highly appreciated!
I have a question (and Issues -.-) with Route-Based IPsec setup.
First of all, I assume, that the Manual (https://docs.opnsense.org/manual/how-tos/ipsec-s2s-conn-route.html) is wrong at the Routes part: there it is stated, that on Site A the network address 10.0.2.0 (which additionally might be a typo as 10.2.0.0 was used) should be set... but 10.2.0.0 is the address of Site A and if one does... this kills the system (I tried in a third shot, as I am unable to get my VPN tunnel working)
For my issue (if anyone is willing to help): I've followed the instructions to 100% with one exception: my site B has no static public IP address... the rest has been kept as stated... (but I also have working policy-based Tunnels on Site A)
So as soon as I provide a Gateway, Site B tries to retransmit: "retransmit 1 of request with message ID 0" and Site A unregisters "05[CFG] vici client 2 unregistered for: list-conn" and finally disconnects... :((
A policy-based Tunnel has been created before as well, but I couldn't figure out how to fix the MTU issue... as soon as a package with a certain size hit the tunnel, the tunnel kept "connected", but no traffic flew through anymore... (tried all the normalization stuff :/)
therefore I tried to give the route-based tunnel a try... without luck as well -.-
Setup:
Site A, OPNsense 24.7.10_2-amd64 on FreeBSD 14.1-RELEASE-p6 (virtualized System) with a static public IP
Site B, OPNsense 24.7.10_2-amd64 on FreeBSD 14.1-RELEASE-p6 (Zima-Board) with a SIM-Card Router and non-static, non-public (incoming) IP / behind NAT
as stated... configured 1:1 like stated in the manual except the static IP parts
any help is highly appreciated!
"