Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
20.7 Legacy Series
»
Connecting to Active Directory (AD) via IPSEC
« previous
next »
Print
Pages: [
1
]
Author
Topic: Connecting to Active Directory (AD) via IPSEC (Read 2617 times)
samnet
Jr. Member
Posts: 61
Karma: 2
Connecting to Active Directory (AD) via IPSEC
«
on:
August 18, 2020, 01:37:18 pm »
Dear sirs;
Im trauggling to find a proper way to connect my opnsense to active directory via ipsec vpn tunnel.
Im sure it will not be the case for ovpn. but the main problem the DC that has AD in is actually using those terrible licensed firewalls that has only ipsec and kerio vpn. so I have configured the ipsec and opnsense is conecting via ipsec to DC and I can ping the AD server.
the crazy part is that I cant get the opnsense to join the AD. Ive done a packet capture and what Im seeing it that AD isnt giving a clear replies. and the funny part is that IPSEC is actually throwing the WAN ip as source. which is bit funny, but can someone share his experience on this??
can this work?
Firewall on AD windows 2012 is off btw.
Logged
----------------------------
Breeding Open Source
M0n0wall -> PfSense -> OpnSense -> Make lots of sense
mimugmail
Hero Member
Posts: 6767
Karma: 494
Re: Connecting to Active Directory (AD) via IPSEC
«
Reply #1 on:
August 18, 2020, 04:54:54 pm »
You have to add the wan IP to phase2 in IPsec.
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
samnet
Jr. Member
Posts: 61
Karma: 2
Re: Connecting to Active Directory (AD) via IPSEC
«
Reply #2 on:
August 18, 2020, 10:58:45 pm »
thx for this, can you pls explain more on how to do this?
Logged
----------------------------
Breeding Open Source
M0n0wall -> PfSense -> OpnSense -> Make lots of sense
mimugmail
Hero Member
Posts: 6767
Karma: 494
Re: Connecting to Active Directory (AD) via IPSEC
«
Reply #3 on:
August 19, 2020, 07:40:58 am »
Add a second phase2 to your IPsec, local net is WAN IP with /32 and remote net is LAN of DC
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
samnet
Jr. Member
Posts: 61
Karma: 2
Re: Connecting to Active Directory (AD) via IPSEC
«
Reply #4 on:
August 19, 2020, 04:41:24 pm »
this is done already from what I recall, the way packets are shown is
Wanip 72.xx.xx.96:45556 to AD server ip 10.xx.x.2:389
ive done a packet capture and I can see 5 requests coming out but no AD handshake
Logged
----------------------------
Breeding Open Source
M0n0wall -> PfSense -> OpnSense -> Make lots of sense
mimugmail
Hero Member
Posts: 6767
Karma: 494
Re: Connecting to Active Directory (AD) via IPSEC
«
Reply #5 on:
August 19, 2020, 08:31:47 pm »
Screenshot of phase2 please
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
20.7 Legacy Series
»
Connecting to Active Directory (AD) via IPSEC