Skip to main content
kentbsece
New Member
October 10, 2016
Solved

IPSEC VPN Using Private IP, point-to-point

  • October 10, 2016
  • 10 replies
  • 15800 views

Hello,

 

I'm currently building a site-to-site IPSEC VPN but I would like to know if its possible to use a private IP (10.10.10.0/30) network. Below is my current configuration.

 

Firewall A:

Port 10: 10.10.10.1/32 Firewall B: Port 9: 10.10.10.2/32

Both port interface is connected using a cross-cable.

 

Problem: I tried to create an IPSEC - Phase 1 but the tunnel is still down.

Thank You

Best answer by rwpatterson

Make sure you build the policies. The tunnels will not come up unless the interesting traffic is requested by policies.

10 replies

ede_pfau
SuperUser
SuperUser
October 10, 2016

hi,

 

and welcome to the forums.

The value of the WAN addresses don't matter. If you're using a PSK, make sure it is identical on both sides (this is IMHO the most common error in failing VPN setups). In phase2, the Quick Mode selectors should be more specific than the '0.0.0.0/0' defaults.

If you need more support, please post the phase1 and phase2 config, along with the policy and the static route which are needed for this to work.

rwpatterson
New Member
October 10, 2016

Make sure you build the policies. The tunnels will not come up unless the interesting traffic is requested by policies.

kentbsece
kentbseceAuthor
New Member
October 11, 2016

rwpatterson wrote:

Make sure you build the policies. The tunnels will not come up unless the interesting traffic is requested by policies.

I tried to build the Phase 2 and it works. My tunnel is now open. I guess phase 2 as well as the policies must be build to established the tunnel.

 

Cheers!

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.