Skip to main content

Questions tagged [ipsec]

Questions relating to IPSEC VPN configuration, operation and troubleshooting specifically.

0 votes
0 answers
52 views

I'm trying to establish an IPSec tunnel between two PFSense routers. I have successfully configured and have established the Phase 1 (ikev2) portion of the connection. It appears that the Phase 2 ...
imlepid's user avatar
  • 101
1 vote
1 answer
95 views

I’m trying to set up a network with the following configuration: My load balancer is a TPlink - E3707-M2 The challenge I’m facing is that pfSense requires a WAN interface with a public IP, but the ...
Recurseed's user avatar
3 votes
1 answer
164 views

I was trying to set up a IPsec tunnel on the firewall. I wonder how do firewall handles the traffic that destined to / originate from the firewall ? Since Interface Profile do not have a option to ...
jacky chong's user avatar
1 vote
1 answer
436 views

I have a meraki VPN mesh which consists of 3 meraki firewalls and 1 OPNSense firewall. There are 3 IKEv2 IPsec connections setup on the OPNSense firewall, one for each meraki. They're all configured ...
user29976520's user avatar
5 votes
2 answers
445 views

The purpose of this question is to improve my ability to technically apply the idea of routing specific traffic through an IPsec tunnel before reaching the Internet. So far the best that I can ...
Anthony's user avatar
  • 51
2 votes
1 answer
131 views

Im working on deploying a reasonable IPsec lifetime policy on our FlexVPN configuration we have. The defaults from Cisco are as follows: router#show crypto ipsec security-association lifetime Security ...
Mario Jost's user avatar
  • 1,761
2 votes
1 answer
488 views

What I have learnt is that whenever protocol X is encapsulated inside another protocol Y, then we say protocol X over protocol Y. eg: we say video over http or text over http, that's because video/...
rooni's user avatar
  • 191
1 vote
0 answers
93 views

I have tried to create a VPN using the FRITZ!Box 6490 builtin service. It has only IPSec available (no Wireguard). I have create a profile for my user and it looks similar to this: VPN-Daten: VPN-Typ: ...
tbrodbeck's user avatar
  • 111
1 vote
1 answer
272 views

In PAN-OS 11.1 I could do "debug ike global on dump" to get some [DEBG] and [DUMP] messages in ikemgr.log from which I could get the SK_ei and SK_er keys that allow me to decode the IKEv2 ...
Bruno Rijsman's user avatar
0 votes
1 answer
154 views

Site A needs IPsec with site B. Site A networks 192.168.20.0/24 and 192.168.50.0/24 need to reach Site B network 192.168.1.0/24. And the other way around as well. The problem is that Site A has a ...
N.K.'s user avatar
  • 3
0 votes
1 answer
186 views

In the Palo Alto document. https://docs.paloaltonetworks.com/network-security/ipsec-vpn/administration/set-up-site-to-site-vpn/set-up-ipsec/set-up-an-ipsec-tunnel Network Security Set Up an IPSec ...
jacky chong's user avatar
0 votes
1 answer
4k views

Problem summary I'm trying to setup a remote access IPsec IKEv2 VPN between a FortiGate firewall (FortiOS v7.2.8) and a native Windows VPN client with certificate based authentication. I've went ...
Hypnosis9616's user avatar
0 votes
1 answer
136 views

With IPsec transport mode we CAN'T have integrity of variable fields (eg TTL and checksum). Why is it a problem? Is it? What could be the attack? I think TTL expire or checksum modification (so both ...
allexj's user avatar
  • 101
0 votes
1 answer
315 views

I'm testing a setup using ASA to provide VPN over L2TP/IPSec PSK to support native IPSec clients such as iOS, Android, MacOS, Windows, etc. The issue I'm running into is that when connected, the split-...
640KB's user avatar
  • 103
1 vote
1 answer
364 views

Given the following 3 subnet topology, I will give names to them to simplify it, I am using planets, I see it as a perfect geographic enumeration. Sites Office on Earth 172.1.x FiOS, default MTU ...
Sam Washington's user avatar

15 30 50 per page
1
2 3 4 5
21