Example 1 – Site-to-site IPsec configuration

In this first example, we will create a tunnel between two networks separated by the internet. This simulates a VPN tunnel that might be set up if we had to connect two facilities run by the same company, but separated by some distance. The endpoints for the tunnels will be the WAN interfaces of two separate pfSense firewalls, and we will have to perform essentially identical configurations on both ends.

We begin by navigating to VPN | IPsec. On the default tab, Tunnels, we set up the Phase 1 entry first, which we begin by clicking on the Add P1 button. In the General Information section, we change the Key Exchange version to IKEv2. We set the Remote gateway to the IP address of the second pfSense ...

Get Mastering pfSense now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.