"Phase1 not configured" after Upgrade and Config Import from old Hardware

Started by wos, January 26, 2026, 11:08:58 AM

Previous topic - Next topic
Hi together,

after upgrading opnsense to other hardware, many things are fine but all my IPsec connections are gone. Dashboard shows only "Phase1 not configured". Is there a way to restore them properly or what is preventing it from appearing in the webgui?

Thanx
Emil

You probably need to install the os-strongswan-legacy plugin.
Hardware:
DEC740

Sorry for not responding, was sick the last days.

Yes. This is the solution!
I understand that something in ipsec section has to be change in 26, and that (now) old legacy stuff, will not more work. But dont know why, and why is there an manual intervention needed?!

So, bevor switching to 26.x the best way, seems to disable the working tunnels P1/P2 and try to set up in the new way (seems that there is to fill connections/presharedkeys) with my existing config manually. When it works then, in that other way, then i can update and my vpns are there, also in 26.x? so i have to wait a bit, for 26.x ... and not to perform the update.

Next month this ipsec connection has to work withou issues, what is the case for sure, if i not make an upgrade. After that i can play with it, how this has to be setup now. Btw. Is there a reason why that old legacy configs, could not be upgraded to the new kind, how to setup ipsec now? or why it is so, that all has to be setup again manually?

The os-strongswan-legacy plugin will continue to work and you don't need any manual intervention yet. It just falls out of the support scope eventually.

There was no automatic migration since ipsec has too many variants, manual decisions must be made when configuring the tunnels again.
Hardware:
DEC740