IPSec tunnel not surviving a reboot nor a network restart

Started by mimizone, March 23, 2023, 05:02:40 PM

Previous topic - Next topic
Hello,
I run the latest version of 22.7 but the same problem happened in the recent 22.x versions

I use an IPSec tunnel from OPNSense to Google GCP Cloud VPN.
The setup works fine typically.

It just doesn't survive a reboot of the router. The configuration is still there, the IPSec interface, the gateway, the static route. It says it's up. The packets show up on the IPSec interface via tcpdump. But the packets are actually not sent to GCP at all. They end up in a blackhole somewhere in OPNSense.
The only way I found to fix this is to stop IPSec, delete phase 2 and phase 1 setup, recreate everything.
I don't have to recreate the GCP side at all.

I observed yesterday the same issue but not after a reboot this time but just because we had lost our internet connection for 2h because of the ISP.

I am considering using another IPSec tunnel software instead of OPNSense if it proves it is a known issue that is not fixed in 22.7 or 23.1 But maybe there is some possible tweak that can be done in OPNSense to make it more reliable?

Thanks for any tips you may have