IPsec {{PLANE_LABEL}}

{{KIND_PILL}}

Bring up an IPsec tunnel to third-party gear — IKEv2 (iked) by default, or IKEv1 (isakmpd) for legacy interop with old equipment. Secrets are stored on the router and referenced by name; the keys never leave the router. Applying replaces the entire IPsec configuration with the tunnel you compose here.

{{#CAN_CERT}}Manage PKI{{/CAN_CERT}}
{{#ERROR}}
{{ERROR}}
{{/ERROR}} {{#FLASH}}
{{FLASH}}
{{/FLASH}} {{#APPLY_JOB}}
{{APPLY_JOB_TITLE}}
This can take a couple of minutes (the validator runs on the router); the page will update when it completes.
{{/APPLY_JOB}} {{#NO_WRITE}}
You have read-only access to IPsec. Changing the configuration needs ipsec:*:write (net-admin role).
{{/NO_WRITE}}

Status

{{DRIFT_LABEL}}

Service

{{ENABLED_LABEL}}

Active plane

{{PLANE_NAME}}

{{DAEMON_LABEL}}

{{RUNNING_LABEL}}

On boot

{{RC_LABEL}}

{{#BOOT_INTENT}}
IPsec is running but is not enabled on boot, so it will not survive a reboot. {{#CAN_WRITE}}
{{/CAN_WRITE}}
{{/BOOT_INTENT}} {{#CAN_WRITE}}
{{/CAN_WRITE}} {{#TOGGLE_FORCE_WAN}}

Confirm IPsec service change

This change touches the management path. Tick to confirm and retry — it runs behind a self-revert window that backs out automatically if it cuts you off.

{{/TOGGLE_FORCE_WAN}} {{#HAS_PREVIEW}}

Live configuration (secrets redacted)

{{PREVIEW}}
{{#PREVIEW_TRUNCATED}}

Preview truncated.

{{/PREVIEW_TRUNCATED}}
{{/HAS_PREVIEW}} {{#PKI_MANAGED}}

Managed CA {{PKI_CA_NAME}} — {{PKI_STATE}}.

{{/PKI_MANAGED}} {{#PF_FORWARDING}}
This configuration also needs net.inet.ip.forwarding=1 and PF rules. Bring up the tunnel, then review the suggested firewall rules below or on the Firewall page.
{{/PF_FORWARDING}}
{{#PENDING}}

Confirm: {{PENDING_WHAT}}

The change is live but touches the management path, so it is awaiting confirmation and reverts automatically in {{PENDING_REMAINING}} seconds unless you keep it. Do not reload or navigate away while this window is open — an abandoned window self-reverts and you lose the Keep option.

{{#PENDING_MGMT}}

Apply the firewall rules first, then confirm.

1. The tunnel is up but unconfirmed (it reverts at the deadline if you do nothing).

2. Apply the suggested PF rules below on the Firewall page and test reachability.

3. Only then tick the box and keep this tunnel.

{{/PENDING_MGMT}} {{#PENDING_PF}}

Suggested firewall rules

{{PENDING_PF_RULES}}
{{#PENDING_PF_FWD}}

Also set net.inet.ip.forwarding=1 (System › Network).

{{/PENDING_PF_FWD}}
{{/PENDING_PF}} {{#PENDING_MGMT}} {{/PENDING_MGMT}}
{{/PENDING}} {{#FORM}}
IKE protocol

IKEv2 is the modern default. IKEv1 (isakmpd) is for legacy interop with old gear that cannot do IKEv2 — pre-shared key, main mode, IPv4 only. Manual (static keys) installs a fixed SADB/SPD entry with no key exchange (no daemon). Applying any plane disables the other (only one runs at a time).

Letters, digits, hyphen, underscore. Used as the policy name and the secret reference.

This router's public IP (IPv4 for the IKEv1 plane).

Tunnel type

The remote gateway's public IP, or any.

Stored in the secret store, never echoed back. Leave blank when re-confirming a tunnel whose key is already stored.

EAP users

Each remote user dials in with a name and password (MSCHAPv2). Passwords are stored on the router and never echoed back.

{{EAP_ROWS}}

Create the CA and issue this router's server certificate on the PKI page first.

Global IKE options
IKEv1 (isakmpd) — pre-shared key, main mode, IPv4 only. There is no EAP or certificate auth on this plane; use it only for legacy site-to-site interop.

The remote gateway's public IPv4 address, or any (passive/dynamic responders only).

Stored in the secret store, never echoed back. Leave blank when re-confirming a tunnel whose key is already stored.

Phase 1 — ISAKMP SA (main mode)

Phase 2 — IPsec SA (quick mode)

Legacy transforms are cryptographically weak. Enable them only to interoperate with old gear that offers nothing stronger. Prefer AES-256 / SHA2-256 / MODP2048 or better whenever the peer supports it.
Manual keying — a static SADB/SPD entry with no IKE daemon and no key exchange. IPv4 only. Use it only for legacy interop where the peer cannot negotiate.
Static keys have no forward secrecy, no automatic rekey, and no replay protection. Both peers must hold the same keys. To rotate: generate new keys and assign a new SPI (many peers reject a key change under the same SPI), then re-apply. After copying a key to the peer, clear your clipboard.

The remote gateway's outer IPv4 address (the SA destination). The local endpoint is the shared Local endpoint above.

Decimal or 0x-hex, in 256–4294967295, and the two must differ. The peer's outbound SPI is your inbound, and vice versa.

Legacy transforms are cryptographically weak. Enable them only to interoperate with old gear that offers nothing stronger. Prefer AES-256 / SHA2-256 whenever the peer supports it.
Keys {{#MK_STORED}}
The keys you applied are stored. Leave the key fields blank to reuse them. Only regenerate if you will also re-key the peer (new key ⇒ new SPI).
{{/MK_STORED}}

Keys are shown once — copy each to the peer now. They are never displayed again; leave the fields blank on a later re-submit to reuse the stored keys.

Traffic flows

The networks carried by the tunnel. Use a CIDR (10.0.1.0/24) or any. The IKEv1 plane is IPv4-only. For an IKEv2 responder this is usually any → the pool.

{{FLOW_ROWS}}
{{#FORCE_WAN}} {{/FORCE_WAN}} {{#SWITCH_ACK}} {{/SWITCH_ACK}} {{#REDUCE_ACK}} {{/REDUCE_ACK}}
{{/FORM}}