Questions tagged [ipsec]
Questions relating to IPSEC VPN configuration, operation and troubleshooting specifically.
310 questions
0
votes
0
answers
52
views
IPSec Phase 2 doesn't establish between two PFSense routers with VTI
I'm trying to establish an IPSec tunnel between two PFSense routers. I have successfully configured and have established the Phase 1 (ikev2) portion of the connection. It appears that the Phase 2 ...
1
vote
1
answer
95
views
How to set up IPsec for pfSense with load balancer in front that provides private IP addresses?
I’m trying to set up a network with the following configuration:
My load balancer is a TPlink - E3707-M2
The challenge I’m facing is that pfSense requires a WAN interface with a public IP, but the ...
3
votes
1
answer
164
views
Firewall Security Policy for traffic that destined to / originate from the firewall
I was trying to set up a IPsec tunnel on the firewall.
I wonder how do firewall handles the traffic that destined to / originate from the firewall ?
Since Interface Profile do not have a option to ...
1
vote
1
answer
436
views
IKEv2 Issues between Meraki and OPNSense
I have a meraki VPN mesh which consists of 3 meraki firewalls and 1 OPNSense firewall. There are 3 IKEv2 IPsec connections setup on the OPNSense firewall, one for each meraki. They're all configured ...
5
votes
2
answers
445
views
Correct idea for an IPsec gateway
The purpose of this question is to improve my ability to technically apply the idea of routing specific traffic through an IPsec tunnel before reaching the Internet.
So far the best that I can ...
2
votes
1
answer
131
views
Recommendations about the volume of IPsec traffic before exchanging a new key
Im working on deploying a reasonable IPsec lifetime policy on our FlexVPN configuration we have. The defaults from Cisco are as follows:
router#show crypto ipsec security-association lifetime
Security ...
2
votes
1
answer
488
views
Difference between GRE over Ipsec and Ipsec over GRE
What I have learnt is that whenever protocol X is encapsulated inside another protocol Y, then we say protocol X over protocol Y. eg: we say video over http or text over http, that's because video/...
1
vote
0
answers
93
views
FRITZ!Box IPSec VPN only gives access to Router but no Device on Network [closed]
I have tried to create a VPN using the FRITZ!Box 6490 builtin service. It has only IPSec available (no Wireguard). I have create a profile for my user and it looks similar to this:
VPN-Daten:
VPN-Typ: ...
1
vote
1
answer
272
views
How to get DEBG messages in ikemgr.log for extracting the SK_ei and SK_er keys (Palo Alto VM-Series PAN-OS 11.2:)
In PAN-OS 11.1 I could do "debug ike global on dump" to get some [DEBG] and [DUMP] messages in ikemgr.log from which I could get the SK_ei and SK_er keys that allow me to decode the IKEv2 ...
0
votes
1
answer
154
views
Fortigate IPsec site-to-site routing issue
Site A needs IPsec with site B.
Site A networks 192.168.20.0/24 and 192.168.50.0/24 need to reach Site B network 192.168.1.0/24. And the other way around as well.
The problem is that Site A has a ...
0
votes
1
answer
186
views
What zone should I assign the tunnel interface to?
In the Palo Alto document.
https://docs.paloaltonetworks.com/network-security/ipsec-vpn/administration/set-up-site-to-site-vpn/set-up-ipsec/set-up-an-ipsec-tunnel
Network Security
Set Up an IPSec ...
0
votes
1
answer
4k
views
Remote access IPsec VPN tunnel connection between FortiGate firewall and native Windows VPN client fails to establish
Problem summary
I'm trying to setup a remote access IPsec IKEv2 VPN between a FortiGate firewall (FortiOS v7.2.8) and a native Windows VPN client with certificate based authentication.
I've went ...
0
votes
1
answer
136
views
Why is IPsec transport mode "vulnerable" for not having integrity of variable fields? Why is this so important?
With IPsec transport mode we CAN'T have integrity of variable fields (eg TTL and checksum). Why is it a problem? Is it? What could be the attack?
I think TTL expire or checksum modification (so both ...
0
votes
1
answer
315
views
Cisco ASA L2TP/IPsec split-tunnel not working for public Internet
I'm testing a setup using ASA to provide VPN over L2TP/IPSec PSK to support native IPSec clients such as iOS, Android, MacOS, Windows, etc.
The issue I'm running into is that when connected, the split-...
1
vote
1
answer
364
views
Pinging packets greater than 1500 between two proper configured machines on proper configured networks, always possible?
Given the following 3 subnet topology, I will give names to them to simplify it, I am using planets, I see it as a perfect geographic enumeration.
Sites
Office on Earth 172.1.x FiOS, default MTU
...