USG 20 L2TP VPN for Android / iOS - Phase 2 proposal

Deffinately not normal listing this many for one S2S VPN. @derelict said in IPSEC Phase 2 Duplicate Causes VPN Tunnel to get stuck: pfSense will show rekeyed P2 entries there. You can get more information with swanctl --list-sas. This is normal. The pfSense node will send traffic using the active SA. That will be the SA that has counters Site-to-Site VPN tunnel options for your Site-to-Site VPN The margin time in seconds before the phase 2 lifetime expires, during which the AWS side of the VPN connection performs an IKE rekey. You can specify a number between 60 and half of the value of the phase 2 lifetime seconds. UniFi - Verifying and Troubleshooting IPsec VPN on USG IP > isakmp: phase 2/others R oakley-quick[E] Note : This is a live capture. If there is no output that means that the traffic is either not being generated on the client, or there is something blocking the traffic upstream.

VPN — IPsec — NAT with IPsec Phase 2 Networks | pfSense

