OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Multiple Roadwarrior IPSEC tunnels?
« previous next »
  • Print
Pages: 1 [2]

Author Topic: Multiple Roadwarrior IPSEC tunnels?  (Read 9624 times)

schnipp

  • Sr. Member
  • ****
  • Posts: 379
  • Karma: 19
    • View Profile
Re: Multiple Roadwarrior IPSEC tunnels?
« Reply #15 on: October 16, 2018, 07:43:10 pm »
So, I am back and added a second mobile connection using the link you mentioned. Afterwards I did some tests, the second connection and two mobile connections using the same virtual ip pool look fine and work in parallel.

But, I found one bug in the GUI. For the additional connection it is not possible to define a phase2 with a subnet which is already defined in the first mobile connection. The GUI shows the following error message during configuration (there is one small adaption of consistency check needed within the backend):

Quote
The following input errors were detected:
    Phase2 with this Local Network is already defined for mobile clients.

Regarding multiple mobile connections which needs to be distinguished the ike daemon gradually tests for a valid configuration :) (see log file excerpt)

Quote
Oct 16 19:26:01    charon: 15[CFG] <con1|8> switching to peer config 'con5'
Oct 16 19:26:01    charon: 15[CFG] <con1|8> selected peer config 'con1' inacceptable: non-matching authentication done
Oct 16 19:26:01    charon: 15[CFG] <con1|8> constraint requires public key authentication, but pre-shared key was used

We should keep in mind, that all clients of the same ip pool can communicate independent to their configured endpoint.
Logged
OPNsense 24.7.9_1-amd64

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Multiple Roadwarrior IPSEC tunnels?
« Reply #16 on: October 23, 2018, 03:38:38 pm »
I was also able to use IKEv1 and v2 with Xauth-PSK and EAP-MSCHAPv2 .. let's see if we can make this into stable :)
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

schnipp

  • Sr. Member
  • ****
  • Posts: 379
  • Karma: 19
    • View Profile
Re: Multiple Roadwarrior IPSEC tunnels?
« Reply #17 on: October 27, 2018, 10:21:42 am »
That sounds good  :)
Logged
OPNsense 24.7.9_1-amd64

  • Print
Pages: 1 [2]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Multiple Roadwarrior IPSEC tunnels?
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2