OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • [SOLVED] IPSec Site to Stte VPN Problem
« previous next »
  • Print
Pages: [1]

Author Topic: [SOLVED] IPSec Site to Stte VPN Problem  (Read 6311 times)

MikeA

  • Newbie
  • *
  • Posts: 7
  • Karma: 0
    • View Profile
[SOLVED] IPSec Site to Stte VPN Problem
« on: November 18, 2015, 04:46:07 pm »
I have a site to site vpn tunnel up and running just fine with one phase 2 tunnel.  I'm trying to add another Phase 2 tunnel, but for whatever reason, I can't get the 2 tunnels to work at the same time.  If I disable Tunnel #1 and reconnect Tunnel #2 works.  If I re-enable Tunnel #1 and disable Tunnel #2 it works.  When both Tunnels are enable, only Tunnel #1 will work.

Both tunnels are on separate subnets.

Any help would on what I can do next would be greatly appreciated.

Thank you.
« Last Edit: January 09, 2016, 01:28:24 am by franco »
Logged

Andreas

  • Sr. Member
  • ****
  • Posts: 272
  • Karma: 9
    • View Profile
Re: IPSec Site to Stte VPN Problem
« Reply #1 on: November 18, 2015, 07:59:46 pm »
Can you send as anonymized the logs?
Logged

MikeA

  • Newbie
  • *
  • Posts: 7
  • Karma: 0
    • View Profile
Re: IPSec Site to Stte VPN Problem
« Reply #2 on: November 18, 2015, 09:41:30 pm »
Where would I find the logs to send?
Logged

Zeitkind

  • Full Member
  • ***
  • Posts: 180
  • Karma: 27
    • View Profile
Re: IPSec Site to Stte VPN Problem
« Reply #3 on: November 18, 2015, 11:02:28 pm »
Quote from: MikeA on November 18, 2015, 04:46:07 pm
Both tunnels are on separate subnets.

Are both sides the same hard/software running?
Many IPSec setups have problems with more than 1 phase-2 tunnels, but work fine with seperate tunnels, i.e. 1 tunnel (with phase 1+2) for each subnet.
e.g.:
Site 1 with LAN 1 --- tunnel --- Site 2 with LAN 2
Site 1 with LAN 1 --- tunnel --- Site 2 with LAN 3
Site 1 with LAN 1 --- tunnel --- Site 2 with LAN 4 behind static route on LAN 2
Site 1 with LAN 1 --- tunnel --- Site 2 with LAN 5 behind static route on LAN 3
Logged

MikeA

  • Newbie
  • *
  • Posts: 7
  • Karma: 0
    • View Profile
Re: IPSec Site to Stte VPN Problem
« Reply #4 on: November 19, 2015, 01:00:09 am »
Actually not sure what the other side is running, but I can find out.  This worked on both my Sonicwall and pfSense with no problems. 

The tunnel shows that it's up and connected, just no traffic.
Logged

MikeA

  • Newbie
  • *
  • Posts: 7
  • Karma: 0
    • View Profile
Re: IPSec Site to Stte VPN Problem
« Reply #5 on: November 19, 2015, 06:00:23 pm »
I'll gladly supply the logs if you point me in the direction of acquiring them.
Logged

fraenki

  • Full Member
  • ***
  • Posts: 175
  • Karma: 29
    • View Profile
    • GitHub
Re: IPSec Site to Stte VPN Problem
« Reply #6 on: December 02, 2015, 12:05:16 am »
Quote from: MikeA on November 18, 2015, 04:46:07 pm
I have a site to site vpn tunnel up and running just fine with one phase 2 tunnel.  I'm trying to add another Phase 2 tunnel, but for whatever reason, I can't get the 2 tunnels to work at the same time.

This is a known issue which will be fixed with release 15.7.21 in a few days, see https://forum.opnsense.org/index.php?topic=1774.msg5552 for further details.


Regards
- Frank
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • [SOLVED] IPSec Site to Stte VPN Problem
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2