Difference between revisions of "IPSec between Edgrouter and PFSense"

From Michael's Information Zone
Jump to navigation Jump to search
Line 2: Line 2:
 
==VyOS conifguration (should be similar to EdgeOS)==
 
==VyOS conifguration (should be similar to EdgeOS)==
 
<pre>
 
<pre>
set vpn ipsec  
+
 
 +
 
 +
set vpn ipsec site-to-site peer <ip or hostname of your peer> default-esp-group esp1
 +
set vpn ipsec site-to-site peer <ip or hostname of your peer> authentication mode pre-shared-secret
 +
set vpn ipsec site-to-site peer <ip or hostname of your peer> authentication pre-shared-secret <your secret>
 +
set vpn ipsec site-to-site peer <ip or hostname of your peer> authentication id <your public IP>
 +
set vpn ipsec site-to-site peer <ip or hostname of your peer> ike-group ike1
 +
set vpn ipsec site-to-site peer <ip or hostname of your peer> local-address <address that listens for ipsec traffic>
 +
set vpn ipsec site-to-site peer <ip or hostname of your peer> tunnel 1 esp-group esp1
 +
set vpn ipsec site-to-site peer <ip or hostname of your peer> local prefix <local lan>
 +
set vpn ipsec site-to-site peer <ip or hostname of your peer> remote prefix <remote lan>
 
</pre>
 
</pre>

Revision as of 16:29, 31 August 2017

[1]

VyOS conifguration (should be similar to EdgeOS)



set vpn ipsec site-to-site peer <ip or hostname of your peer> default-esp-group esp1
set vpn ipsec site-to-site peer <ip or hostname of your peer> authentication mode pre-shared-secret
set vpn ipsec site-to-site peer <ip or hostname of your peer> authentication pre-shared-secret <your secret>
set vpn ipsec site-to-site peer <ip or hostname of your peer> authentication id <your public IP>
set vpn ipsec site-to-site peer <ip or hostname of your peer> ike-group ike1
set vpn ipsec site-to-site peer <ip or hostname of your peer> local-address <address that listens for ipsec traffic>
set vpn ipsec site-to-site peer <ip or hostname of your peer> tunnel 1 esp-group esp1
set vpn ipsec site-to-site peer <ip or hostname of your peer> local prefix <local lan>
set vpn ipsec site-to-site peer <ip or hostname of your peer> remote prefix <remote lan>