legacy ipsec settings on 26.7..1_1

Started by tentpig, August 07, 2026, 11:00:03 PM

Previous topic - Next topic
Just converted from pfSense to Opnsense. Running 26.7.1_1.

have a client with some legacy ipsec gear I need to connect to. They are set up with AES 256 SHA1 DH2.

I cannot see how to configure this in the GUI.

Can someone provide guidance? Googling yields instructions which don't correspond to anything I see on the screen, so I assume they're for an older version of the software.

There has been a lot of IPSec talk lately because of some issues and there is also the fact that there are both a Legacy and a Current way to set things up IIRC so you need to figure all that stuff out first before you start !!


Good luck! :)
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

Quote from: nero355 on August 08, 2026, 01:36:51 PMThere has been a lot of IPSec talk lately because of some issues and there is also the fact that there are both a Legacy and a Current way to set things up IIRC so you need to figure all that stuff out first before you start !!

Unfortunately, I see no way to activate any form of "legacy" settings. All attempts to google this yield references to a page in OpnSense which apparently no longer exists, and a few results indicate the functionality was folded into the Connections page. However, on the Connections page, although there is a AES256-SHA1 setting in the drop-down, there's no way to select DH2 (which I believe translates into modp1024). Thus when I attempt to connect, I get a NO_PROPOSAL error.

I really, really, really do not want to have to regress to pfSense to resolve this. I've asked the client to upgrade their IPSEC hardware but that is going to take time for approvals and what not.