Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A pfSense site-to-site IPsec VPN connects selected networks at two locations. Configure a Phase 1 peer relationship, then one or more Phase 2 definitions for the networks that should communicate. Both firewalls must agree on compatible settings—and a tunnel showing as established still needs the right firewall rules and routes to carry traffic.

What you need before configuring the tunnel

Gather the details for both sites before opening the configuration page. You will need each peer’s outside address, the LAN subnet or subnets behind it, the authentication method, and confirmation of whether both endpoints support IKEv2. Also identify the local and remote peer IDs each device will use; an ID may differ from the outside address, so match the configured identities rather than assuming they are the same.

  • Site A and Site B outside peer addresses: The addresses the endpoints use to reach one another.
  • Protected networks: The LAN subnet or subnets at each site, written with their correct masks.
  • Authentication and proposals: Mutually supported Phase 1 and Phase 2 settings, including key exchange, encryption, authentication, lifetimes, and PFS where applicable.
  • Routing and policy design: Whether this will be a policy-based tunnel or a route-based tunnel using a VTI.

Netgate’s configuration guidance recommends IKEv2 when both endpoints support it. If one peer cannot use IKEv2, choose a version both devices support and configure the corresponding settings consistently. Netgate: IPsec configuration

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Understand Phase 1 and Phase 2

Phase 1: establish the peer relationship

Phase 1 negotiates the relationship between the two IPsec peers. Its settings include the IKE version, peer identities, authentication, and the proposal used to establish the secure connection. If these values are incompatible, the peers cannot establish the tunnel.

#1 Best Overall
Netgate 1100 pfSense+ Security Gateway - Firewall, Router, VPN
  • BUSINESS READY - pfSense+ software updates included for product lifetime. Netgate TAC Lite technical support included. One year hardware warranty included.
  • COMPLETE - Pre-loaded with pfSense+ software to get up and running fast. Simply unbox it and start customizing for your secure edge networking needs. Free help with setup from our expert Technical Assistance Center (TAC) available 24/7/365.
  • POWERFUL - A dual core ARM Cortex-A53 1.2 GHz delivers near gigabit routing of common home iPerf3 traffic and in excess of 650 Mbps of firewall throughput.
  • COMPACT - Low power draw, a compact form factor, and silent operation allow it to run unnoticed when placed on a desktop, wall, or rack.
  • FLEXIBLE - Three (3) 1 GbE switched (WAN/LAN/OPT) ports allow you to configure three separate 1 GbE switched ports for upto a gigabit of bi-directional traffic.

Phase 2: define protected traffic

Each Phase 2 definition describes the traffic to protect and the security association for that traffic. A tunnel has one Phase 1 definition and can have one or more Phase 2 definitions—for example, separate entries when a site needs to reach multiple remote subnets. The local and remote network selectors, masks, and cryptographic settings must line up across both endpoints.

In pfSense, manage IPsec definitions under VPN > IPsec. Use Netgate’s IPsec documentation for the current interface details.

Rank #2
Netgate 2100 TAA pfSense+ Security Gateway - Firewall, Router, VPN
  • SECURE - Your best pfSense+ Firewall, Router, and VPN solution. #1 ranked "best firewalls" solution on PeerSpot (June 2025). 10+ million installations around the world. Flexible to solve your specific networking needs.
  • COMPLETE - Pre-loaded with pfSense+ software to get up and running fast. Simply unbox it and start customizing for your secure edge networking needs. Free help with setup from our expert Technical Assistance Center (TAC) available 24/7/365.
  • PRIVATE - Enterprise-grade VPN without breaking the bank. Virtual private network protocols including IPsec, OpenVPN and WireGuard VPN.
  • BUSINESS READY - Free pfSense+ software updates, free training, free forums, free comprehensive documentation, free technical assistance included for the LIFETIME of the appliance. One year hardware warranty included.
  • POWERFUL - A 1.2 GHz ARM Cortex-A53 processor delivers 2.20 Gbps of routing for common iPerf3 traffic and over 964 Mbps of firewall throughput for added security and high-performance service for your small business network.

Choose policy-based or route-based IPsec

Choose the tunnel mode to suit the peer and the way the network is routed. Neither mode is universally best.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Mode How it handles traffic When it fits
Policy-based Phase 2 network selectors and policies match the traffic to protect. A common choice, especially when compatibility with third-party IPsec implementations is important.
Route-based (VTI) Uses a virtual tunnel interface; Phase 2 addresses that interface rather than serving as the policy selector. Useful when the design needs a tunnel interface to participate in normal routing.

For implementation details, see Netgate’s route-based IPsec (VTI) guidance. Verify that the other firewall supports the chosen mode and that both sides use a compatible design.

Rank #3
Netgate 4200 MAX pfSense+ Security Gateway - Firewall, Router, VPN
  • BUSINESS READY - pfSense+ software updates included for product lifetime. Netgate TAC Lite technical support included. One year hardware warranty included.
  • POWERFUL - Experience multi-gigabit throughput. 4-Core 2.1 GHz Intel Atom C1110 CPU, 4GB LPDDR5 RAM - Delivers 9.28 Gbps routing for IMIX traffic and 8.61 Gbps of firewall throughput.
  • FLEXIBLE - 4 discrete, unswitched 2.5 Gbps ports, re-configurable as WAN or LAN ports. Supports dual WAN configurations.
  • SECURE - Flexible virtual private network protocols including IPsec, OpenVPN and WireGuard VPN. Includes Intel Advanced Vector Extensions 2 (AVX2) instructions that support faster encryption and cryptographic processing.
  • COMPLETE - Pre-loaded with pfSense+ software to get up and running fast. Simply unbox it and start customizing for your secure edge networking needs. Free help with setup from our expert Technical Assistance Center (TAC) available 24/7/365.

Configure the peers in pfSense

  1. Open VPN > IPsec. Start with Phase 1 and select the IKE version supported by both peers; prefer IKEv2 when possible.
  2. Set the peer and identities. Enter the remote gateway address, the appropriate local and remote IDs, and the shared authentication method. If using a pre-shared key, use a strong, unique key and configure the same value on both endpoints.
  3. Set a compatible Phase 1 proposal. Compare the actual algorithms, key exchange/DH group, authentication, and lifetime with the other firewall. Names for equivalent settings differ across vendors, so match what the options do rather than relying on labels alone.
  4. Add Phase 2 entries for the protected networks. Set the local and remote network addresses and masks correctly, then choose compatible encryption, authentication, lifetime, and PFS settings. Add further entries if the design requires additional network pairs.
  5. Apply matching settings on the other endpoint. Confirm that its peer IDs, proposals, selectors, and authentication settings correspond to the pfSense configuration.
  6. Allow and verify traffic. Review the IPsec firewall rules and routes at both sites, then initiate traffic between the intended hosts and check the IPsec status and logs.

When a peer offers many selectable algorithms and it is unclear which will be negotiated, Netgate recommends narrowing the choices to one believed-compatible option and checking logs on both sides after initiating traffic. Consult Netgate’s third-party IPsec guidance for cross-vendor considerations.

Diagnose the failure by where it occurs

The tunnel does not establish

  • Check that the IPsec service is running and inspect firewall logs for blocked UDP 500 or UDP 4500 traffic.
  • Compare Phase 1 and Phase 2 settings on both endpoints, paying particular attention to peer IDs, DH and PFS choices, authentication, network selectors, and subnet masks. Netgate Documentation identifies configuration mismatch as the single most common cause of failed IPsec tunnel connections. Netgate: IPsec troubleshooting
  • If NAT is present or an intermediate device mishandles ESP, NAT Traversal (NAT-T) carries ESP inside UDP 4500. It is generally detected automatically; check that the path does not block the required traffic.

Phase 1 completes but Phase 2 does not

In the IPsec log, IKE_SA ... established indicates that Phase 1 completed, while CHILD_SA ... established indicates that Phase 2 completed. If the first appears but the second does not, concentrate on Phase 2 compatibility: compare selectors and masks, encryption and authentication proposals, and PFS settings on both peers. A successful IKE relationship alone does not mean a protected traffic association was created. Netgate’s IPsec log guidance describes these messages and diagnostic logging.

Rank #4
Firewall Mini PC, Intel J1900 4-Port i210 Router, 4GB RAM 64GB SSD
  • 【CPU Optimized for Firewall Mini PCs】This firewall appliance is powered by Intel Quad-Core Celeron J1900, 64-bit, up to 2.0 GHz, supporting software-based encryption. Energy-efficient and reliable, it runs 24/7 for home or small office networks, handling VPNs, multi-WAN routing, and basic firewall tasks efficiently.
  • 【4×Intel i210 Ports】Equipped with four Intel i210 network controllers, each delivering up to 1 GbE for reliable multi-WAN routing, VPN connections, VLAN management, and stable performance in small office or home firewall deployments
  • 【Memory & Storage】This Firewall Mini PC comes with 4 GB DDR3L RAM and a 64 GB mSATA SSD, providing reliable performance for basic networking tasks. AMI BIOS with ACPI support ensures stable system operation and energy-efficient 24/7 use
  • 【Flexible System Compatibility】Compatible with Windows 10, Linux, and professional firewall systems such as pfSense, OPNsense, and VyOS, ensuring stable network management for home or small office use
  • 【After-Sales Support:】This compact, fanless, and silent firewall keeps your network secure. Includes lifetime technical support and a 30-day money-back guarantee!

The tunnel is established but traffic does not pass

  • Check the IPsec firewall rules tab and the firewall logs at both sites. A negotiated security association does not bypass firewall policy.
  • Verify the Phase 2 selectors identify the intended local and remote networks, including their masks.
  • Inspect routes and policy-routing rules to ensure traffic takes the intended path through the tunnel.
  • Confirm that LAN clients send traffic to pfSense and that hosts at the far end have a valid return path. A request can cross the tunnel while its reply is sent somewhere else.

Separate tunnel negotiation from end-to-end forwarding: first confirm the relevant Phase 1 and Phase 2 associations, then trace the traffic and its return path. The Netgate troubleshooting guide covers common traffic-flow checks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Make relevant log messages easier to isolate

For diagnosis, Netgate recommends setting IKE SA, IKE Child SA, and Configuration Backend log settings to Diag, with other IPsec log settings at Control. Manually initiating the tunnel can make the resulting messages easier to isolate. Restore normal logging when detailed diagnostics are no longer needed.

Best Value
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Account for load without weakening security by default

A low-end firewall can miss Dead Peer Detection (DPD) exchanges when its CPU is saturated by high bandwidth usage, causing tunnels to drop. Treat DPD failures that coincide with heavy load as a capacity signal: measure appliance utilization and traffic before considering a more capable firewall or acceleration.

Netgate’s scaling guidance discusses QAT, IPsec-MB, and AES-NI-capable hardware, and notes that some Netgate appliances include QAT, CESA, or SafeXcel acceleration. Throughput depends on the hardware and chosen algorithms; a fastest-performing combination is not necessarily the strongest security choice. Evaluate performance and security together, prefer modern mutually supported settings, and document any compatibility-driven downgrade instead of choosing weak algorithms or keys just to make a tunnel connect. Netgate: hardware performance tuning

Quick Recap

Bestseller No. 1
Netgate 1100 pfSense+ Security Gateway - Firewall, Router, VPN
Netgate 1100 pfSense+ Security Gateway - Firewall, Router, VPN
Ideal for AI security: Protect your AI workloads and data.
$299.00
Bestseller No. 2
Netgate 2100 TAA pfSense+ Security Gateway - Firewall, Router, VPN
Netgate 2100 TAA pfSense+ Security Gateway - Firewall, Router, VPN
Ideal for AI security: Protect your AI workloads and data.
$679.00
Bestseller No. 3
Netgate 4200 MAX pfSense+ Security Gateway - Firewall, Router, VPN
Netgate 4200 MAX pfSense+ Security Gateway - Firewall, Router, VPN
Ideal for AI security: Protect your AI workloads and data.
$829.00
SaleBestseller No. 5

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.