conn con10 keyexchange = ikev2 dpdaction = clear dpddelay = 300s eap_identity = "mangel@gmx.de" leftauth = eap-mschapv2 left = %defaultroute leftsourceip = %config forceencaps = yes right = pl82.nordvpn.com rightauth = pubkey rightsubnet = 54.204.25.0/28,23.23.189.144/28,34.195.253.0/25 rightid = pl82.nordvpn.com rightca = "/C=PA/O=NordVPN/CN=NordVPN Root CA/" type=tunnel auto=start
<opt3> <if>tun0</if> <descr>NordVPN</descr> <enable>1</enable> <spoofmac/> </opt3>
conn NordVPN_IPsec keyexchange = ikev2 dpdaction = clear dpddelay = 300s forceencaps = no installpolicy = no left = %WAN-IP right = VPNSERVER leftsubnet = 0.0.0.0/0 rightsubnet = 0.0.0.0/0 leftsourceip = %config4 leftauth = eap-mschapv2 eap_identity = "EMAIL-ACCOUNT" rightid = %VPNSERVER rightauth = pubkey rightca = "/C=PA/O=NordVPN/CN=NordVPN Root CA/" esp = aes256-md5,aes256-sha1,aes192-md5,aes192-sha1,aes128-md5,aes128-sha1,blowfish256-md5,blowfish256-sha1,blowfish192-md5,blowfish192-sha1,blowfish128-md5,blowfish128-sha1,3des-md5,3des-sha1,cast128-md5,cast128-sha1! type = tunnel auto = start
root@OPNsense:/usr/local/etc # ifconfig enc0enc0: flags=41<UP,RUNNING> metric 0 mtu 1536 nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> groups: encroot@OPNsense:/usr/local/etc # ifconfig tun0tun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> metric 0 mtu 1500 options=80000<LINKSTATE> inet6 fe80::6a05:caff:fe23:1654%tun0 prefixlen 64 scopeid 0xc inet 10.6.6.131 --> 10.6.6.131 netmask 0xffffffff nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> groups: tun Opened by PID 7135root@OPNsense:/usr/local/etc # route -4 show 10.6.6.131 route to: 10.6.6.131destination: 10.6.6.131 fib: 0 interface: tun0 flags: <UP,HOST,DONE,PINNED,LOCAL> recvpipe sendpipe ssthresh rtt,msec mtu weight expire 0 0 0 0 1500 1 0
Aug 23 17:19:07 charon: 12[KNL] <NordVPN_IPsec|1> querying policy 10.6.6.131/32 === 0.0.0.0/0 out failed, not foundAug 23 17:18:48 charon: 12[ENC] <NordVPN_IPsec|1> parsed INFORMATIONAL response 7 [ ]Aug 23 17:18:48 charon: 12[NET] <NordVPN_IPsec|1> received packet: from 134.19.189.123[4500] to 192.168.178.25[4500] (80 bytes)Aug 23 17:18:48 charon: 12[NET] <NordVPN_IPsec|1> sending packet: from 192.168.178.25[4500] to 134.19.189.123[4500] (128 bytes)Aug 23 17:18:48 charon: 12[ENC] <NordVPN_IPsec|1> generating INFORMATIONAL request 7 [ N(ADD_4_ADDR) N(ADD_4_ADDR) N(ADD_4_ADDR) N(ADD_4_ADDR) N(ADD_4_ADDR) ]Aug 23 17:18:48 charon: 12[IKE] <NordVPN_IPsec|1> sending address list update using MOBIKEAug 23 17:18:48 charon: 15[IKE] <NordVPN_IPsec|1> peer supports MOBIKEAug 23 17:18:48 charon: 15[IKE] <NordVPN_IPsec|1> CHILD_SA NordVPN_IPsec{1} established with SPIs c072bb4a_i cad3dd39_o and TS 10.6.6.131/32 === 0.0.0.0/0Aug 23 17:18:48 charon: 15[CFG] <NordVPN_IPsec|1> selected proposal: ESP:AES_CBC_256/HMAC_MD5_96/NO_EXT_SEQAug 23 17:18:48 charon: 03[KNL] interface tun0 activatedAug 23 17:18:48 charon: 03[KNL] interface tun0 appearedAug 23 17:18:48 charon: 15[LIB] <NordVPN_IPsec|1> created TUN device: tun0Aug 23 17:18:48 charon: 15[IKE] <NordVPN_IPsec|1> installing new virtual IP 10.6.6.131Aug 23 17:18:48 charon: 15[CFG] <NordVPN_IPsec|1> handling INTERNAL_IP4_NETMASK attribute failedAug 23 17:18:47 charon: 15[IKE] <NordVPN_IPsec|1> installing DNS server 103.86.99.100 via resolvconfAug 23 17:18:47 charon: 15[IKE] <NordVPN_IPsec|1> installing DNS server 103.86.96.100 via resolvconfAug 23 17:18:47 charon: 15[IKE] <NordVPN_IPsec|1> maximum IKE_SA lifetime 10664sAug 23 17:18:47 charon: 15[IKE] <NordVPN_IPsec|1> scheduling reauthentication in 10124s