IPSEC "Connections"damaged my tunnel,fresh install does not generate tunnel conf

Started by zhladik, March 23, 2023, 01:00:49 AM

Previous topic - Next topic
Hello,

After upgrading from 22.7 to 23.1.3 my IPSEC tunnel link stopped working.
Because VPN link was not critical and I decided to clean up my config so
I installed fresh 23.1 from scratch. and immediately updated to 23.1.4_1.

As the first thing I tried to config IPSEC tunnel by new "Connections (swantcl.conf)"
way. But I missed any doc, (it supposes experienced StrongSwan experts only?),
so I returned to the "legacy - Tunnel settings" way.

But it seems that any setting of legacy tunnel phase1 does not generate config files for
tunnels. /usr/local/etc/ipsec.conf nor stongswanc.conf. does not reflect any GUI config.

In partialy updated OPNsense IPSEC doc there is an announced "feature freeze on tunnels" in future.
But it seems that legacy tunnel related code is removed too soon.

Any tips on what to check? Maybe I missed some critical step on IPSEC building/activation, but log files
have no glue for me..

I have not much experience with IPSEC, but i am fluent in linux/bsd CLI, so I looked at scripts
and logs, tried to start things from cli, etc. But maybe not enough deep to find where is problem.