Now that phase 1 of your IPsec tunnel is created, you need to add a child P2 tunnel to it.
To do this, click on "Show Phase 2 Entries" for the IPsec P1 tunnel you have just created.
Then click on: Add P2.
On the "Edit Phase 2" page that appears, configure these settings:
In our case, we configure these settings like this:
Source : NAT with IPsec Phase 2 Networks | pfSense Documentation.
In the "Phase 2 Proposal (SA/Key Exchange)" section, you can configure how encryption and key exchange is managed:
In this section, on site 1 (Brussels), configure these settings:
In the "Expiration and Replacement" section, you can specify the lifetime of the P2 tunnel, the time after which new keys are regenerated for this P2 tunnel, as well as the random value to prevent the 2 peers from trying to regenerate in the keys at the same time as was already the case when configuring tunnel P1.
Then, in the "Keep Alive" section, you can configure the settings:
On site 1 (Brussels), indicate "3600" for the "Life Time" parameter.
Then click Save.
Source : IPsec Configuration - Phase 2 Settings | pfSense Documentation.
Click: Apply Changes.
Your P2 tunnel has been created.
On site 1 (Brussels), go to: Firewall -> Rules.
Then go to the "IPsec" tab and click: Add.
For this firewall rule, configure these settings:
Next, configure these settings:
Click Save.
Click: Apply Changes.
Traffic coming from site 2 (Paris) is authorized.
Although not always necessary, if pfSense is not the default gateway for client PCs or servers at Site 1 (Brussels), network traffic may unnecessarily pass through the client or server PC's default gateway instead. to use the IPsec tunnel directly.
To resolve this slight problem, simply go to: System -> Routing.
Source : Client Routing and Gateway Considerations | pfSense Documentation.
On the "System / Routing / Gateways" page that appears, click: Add.
On the "Edit Gateway" page that appears, configure these settings:
Then click Save.
Click: Apply Changes.
Your LAN gateway appears in the list.
Firewall 7/25/2025
Firewall 8/27/2025
Firewall 8/20/2025
Firewall 7/23/2025
Pinned content
Contact
® InformatiWeb-Pro.net - InformatiWeb.net 2008-2022 - © Lionel Eppe - All rights reserved.
Total or partial reproduction of this site is prohibited and constitutes an infringement punishable by articles L.335-2 and following of the intellectual property Code.
No comment