Now that pfSense is correctly configured on site 1 (Brussels), you just need to configure almost the same thing on site 2 (Paris).
Warning : certain parameters will need to be configured slightly differently to avoid, for example, that the 2 pfSense machines each try to establish the same IPsec tunnel at the same time.
As a reminder, if pfSense uses a private (local) IP address for its WAN interface, it is important to disable the "Block private networks and loopback addresses" option on the "Interfaces -> WAN" page.
Second reminder, all screen prints on a black background (as below) concern the pfSense machine from site 2 (Paris) so that it is clearer to follow.
Then, don't forget to click "Apply Changes" at the top of the page after saving your WAN interface configuration.
To configure phase 1 of the IP sec tunnel on site 2 (Paris), go to: VPN -> IPsec.
Click on: Add P1.
On the "Edit Phase 1" page, configure these settings:
For authentication and encryption algorithm to use, indicate exactly the same as on site 1.
To know :
Warning : make sure to indicate the same secret pre-shared key as that configured for tunnel P1 of site 1 (Brussels).
Warning : to prevent the IPsec tunnel from being able to expire at the same time on both sides and to prevent the 2 peers from each trying to reset the same IPsec tunnel at the same time, you must indicate a lifetime for the P2 tunnel which corresponds to 110% of the value configured on the other peer for this tunnel P1.
Which gives in our case "31600" (given that the value used on site 1 (Brussels) was "28800").
At the bottom of the page, configure these 2 parameters:
Click Save.
Click: Apply Changes.
Your P1 tunnel on site 2 (Paris) has been created.
Firewall 8/8/2025
Firewall 8/6/2025
Firewall 6/6/2025
Firewall 8/20/2025
Pinned content
Contact
® InformatiWeb-Pro.net - InformatiWeb.net 2008-2022 - © Lionel Eppe - All rights reserved.
Total or partial reproduction of this site is prohibited and constitutes an infringement punishable by articles L.335-2 and following of the intellectual property Code.
No comment