Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Virtual private networks
»
IKE v2 - cannot get it to work on latest version
« previous
next »
Print
Pages: [
1
]
Author
Topic: IKE v2 - cannot get it to work on latest version (Read 860 times)
_pX_
Newbie
Posts: 3
Karma: 0
IKE v2 - cannot get it to work on latest version
«
on:
September 13, 2023, 06:20:35 pm »
Hi, I've got a few OPNsense installations with some VPN (roadwarrior and also site-to-site) but cannot get road warior scenario to work on latest version of OPNsense.
Does the guide is still valid for the new version? I went through using Tunnel Setting (legacy) and it doesn't work for me - I get 809 error on Windows Ras client. I tried two different installations, on two different locations.
Any thoughts?
Logged
Monviech (Cedrik)
Global Moderator
Hero Member
Posts: 1601
Karma: 176
Re: IKE v2 - cannot get it to work on latest version
«
Reply #1 on:
September 13, 2023, 08:28:43 pm »
Maybe this can help you.
https://forum.opnsense.org/index.php?topic=35840.0
Logged
Hardware:
DEC740
_pX_
Newbie
Posts: 3
Karma: 0
Re: IKE v2 - cannot get it to work on latest version
«
Reply #2 on:
September 13, 2023, 09:31:11 pm »
Thank you.
Tried method 1 without success - still getting error 809 in Windows RAS Client.
I use self signed certs like in old manual - is this OK?
Also you omitted
local name
in
Pre-Shared Keys
but there is no way to save such a combo...
Another question: does the user name in client should be written as "
john
" or "
john@fqdn
"?
Logged
Monviech (Cedrik)
Global Moderator
Hero Member
Posts: 1601
Karma: 176
Re: IKE v2 - cannot get it to work on latest version
«
Reply #3 on:
September 13, 2023, 10:11:11 pm »
EDIT: You were right I corrected the mistake.
In pre shared keys the type is EAP and not PSK.
And the username can be anything you want, you can also just use john. In the client it has to be written the same as in the EAP Local Identifier. (So if the eap local identifier is john@fqdn, in the client the username is also john@fqdn)
Self signed certificate should still work if the certificate chain. is in the window certificate store.
Also please verify that your firewall accepts udp 500 and udp 4500 and esp on the WAN port. The new IPsec configurations don't automatically add firewall rules anymore.
I have tested both configurations thoroughly so your feedback is really welcome if you find mistakes somewhere.
«
Last Edit: September 16, 2023, 07:10:34 pm by Monviech
»
Logged
Hardware:
DEC740
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Virtual private networks
»
IKE v2 - cannot get it to work on latest version