Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
23.1 Legacy Series
»
New IPSEC guides?
« previous
next »
Print
Pages: [
1
]
Author
Topic: New IPSEC guides? (Read 799 times)
ThyOnlySandman
Jr. Member
Posts: 85
Karma: 4
New IPSEC guides?
«
on:
March 20, 2023, 01:33:19 am »
Does anyone know of a
good
GUI guide for the new 23.x IPSEC policy setup? (swantcl.conf)
Following below example I cannot get a tunnel to come up. Nor do I see anything under IPSEC log? Does "new connections" even use GUI IPSEC log? Or is that just for "legacy" IPSEC tunnels only?
I've setup a lab exactly like this example just with different subnets.
https://docs.opnsense.org/manual/how-tos/ipsec-s2s-conn.html
Logged
Lokutos
Newbie
Posts: 10
Karma: 0
Re: New IPSEC guides?
«
Reply #1 on:
March 20, 2023, 02:02:22 am »
What do you need?
first answer, yes the Log file is used... (switch to debug give most errors if something not work)
if you give me you info what kind of VPN you want to create i can give you a guide how to setup.
VTI or policy based?
(i recomend VTI / Routed)
Logged
ThyOnlySandman
Jr. Member
Posts: 85
Karma: 4
Re: New IPSEC guides?
«
Reply #2 on:
March 20, 2023, 02:28:14 am »
Well - I've been first trying to learn policy based with public keys.
I'm finally making some progress. Had several issues.
My VMware lab switches / environment needed adjustment.
The legacy tunnel settings section needs "ipsec enabled" at bottom is for new policy connections.
I had IKE proposal set to aes256gcm16-ecp521 which is apparently not the proper AEAD algorithm? Switched to aes256gcm16-sha512-x25519 and tunnel finally came up. (I really need to spend some time learning these)
And finally "New connections" apparently doesn't auto add ESP rule to WAN? Also missing UDP 500 + 4500 yet tunnel working without after just adding ESP?
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
23.1 Legacy Series
»
New IPSEC guides?