pfSense Site to Site VPN with IPsec: Step-by-Step Guide (2026)

A pfSense site to site VPN connects two offices (or your home lab and a server somewhere) so devices on both LANs can reach each other as if they were on one network. On pfSense the standard way is IPsec: a Phase 1 entry on each firewall to build the tunnel, a Phase 2 entry for the subnets, and one firewall rule on the IPsec tab. You set up the same few entries on both firewalls.

The Short Version

  1. Make sure the two LANs use different subnets (for example 192.168.1.0/24 and 192.168.2.0/24).
  2. On both firewalls: VPN, IPsec, Add P1. Remote Gateway is the other side’s WAN IP, same pre-shared key on both.
  3. Add a Phase 2 with your LAN as Local Network and the other LAN as Remote Network.
  4. Firewall, Rules, IPsec: allow traffic from the remote subnet.
  5. Check Status, IPsec and ping a host on the other side.

👀 This Tutorial has some related Articles!
👉 The Complete pfSense Fundamentals Bootcamp
👉 Install pfSense from USB – The Complete Guide
👉 Install pfSense on VirtualBox
👉 The Complete pfSense OpenVPN Guide
👉 The Complete pfSense DMZ Guide
👉 Generate SSL Certificates for HTTPS with pfSense
👉 The Complete pfSense Squid Proxy Guide (with ClamAV!)
👉 pfSense Site-to-Site VPN Guide
👉 pfSense Domain Overrides Made Easy
👉 pfSense Strict NAT (PS4,PS5,Xbox,PC) Solution
👉 The Best pfSense Hardware
👉 Traffic Shaping VOIP with pfSense
👉 pfSense OpenVPN on Linux – Setup Guide
👉 pfSense Firewall Rule Aliases Explained
👉 Email Notifications with pfSense
👉 pfSense DNS Server Guide

The Scenario: pfSense Site to Site VPN

I try to keep this example scenario as simple as possible, therefore I created an easy-to-understand, self-explaining diagram.

pfSense IPSec site to site
Overview

This should give you a pretty good understanding of what we want to achieve. We simply want to establish a pfSense site-to-site VPN connection between pfSense #1 HQ and pfSense #2 Remote Location. To do this, we need to create IPSec tunnels and firewall rules on both sides. I kept the subnets simple so you don’t get confused by too many different IPs. The Gateway in your case would be your WAN IP Address.

Settings Both Sides Must Agree On

Most broken tunnels come down to one side using a different value than the other. Pick these before you touch either firewall and use them on both. They follow Netgate’s current recommendations:

SettingPhase 1Phase 2
Key Exchange versionIKEv2
AuthenticationMutual PSK (same key on both sides)
EncryptionAES, 256 bitsAES256-GCM, or AES 256
HashSHA256None with GCM, otherwise SHA256
DH / PFS group14 (2048 bit)14 (2048 bit)
Lifetime28800 seconds3600 seconds

The steps below use PFS group 15 instead of 14. That works too. What matters is that both firewalls use the same group.

The screenshots are from an older pfSense release. The field names haven’t changed, but current pfSense CE and pfSense Plus add a few options, like Child SA Start Action and Child SA Close Action. Leave them on default for a basic tunnel. If you want one side to only answer and never start the tunnel, set Child SA Start Action to “None (Responder Only)” on that side.

Step 1 – Creating IPSec Phase 1 on pfSense #1 HQ

To create a pfSense site-to-site VPN, you need to log in to your pfSense #1 HQ and navigate to VPN / IPsec and click on + Add P1. Set the address of the Remote Gateway and a Description.

  1. IP of your WAN Interface on your pfSense #2 Remote Location
  2. Enter a Description
pfSense IPSec site to site
General Information

Scroll down to Phase 1 Proposal (Authentication). Now head to any page you like, or this one, to create a Pre-Shared Key.

You can also use the tool pwgen on Linux with the following command to create a key:

pwgen -sy 25
pfSense IPSec site to site
Creating a Pre-Shared Key

Copy this key and paste it into the Pre-Shared Key field.

pfSense IPSec site to site
Pasting the Key

Before you save, check the Phase 1 Proposal section against the table above: IKEv2, AES 256 bits, SHA256, DH group 14. Then scroll down, click Save, and click Apply Changes.

Step 2 – Creating IPSec Phase 2 on pfSense #1 HQ

Time to create the second Phase. Click on + Show Phase 2 Entries and click on + Add P2.

pfSense IPSec site to site
Creating Phase 2

Now enter values like in the following example:

  1. On Local network choose Network
  2. Enter the Subnet of your Local Network (192.168.1.0/24 for pfSense #1 HQ)
  3. On Remote Network choose Network
  4. Enter the Subnet of your Remote Network (192.168.2.0/24 for pfSense #2 Remote Location)

Enter a description if you want.

pfSense IPSec site to site
Configuring

Scroll down to Phase 2 Proposal (SA/Key Exchange). Enter values like in the following example:

  1. Change AES Encryption to 256 bits
  2. Change PFS key group to 15 (3072 bit)
  3. Enter the pfSense #2 Remote Location’s IP Address to be pinged automatically (this ensures that the tunnel stays active at all times)
  4. Smash that Save button (Sorry, watched too many YouTube videos)
  5. Hit Apply Changes
pfSense IPSec site to site
Configuring Phase 2

Almost done with pfSense #1, now we just need to create a Firewall Rule for the IPsec interface.

Step 3 – Creating a Firewall Rule on pfSense #1 HQ

Navigate to Firewall / Rules / IPsec. Click on Add. Enter values as the following:

  1. Change Protocol to Any
  2. For Source select Network
  3. Enter the Subnet of pfSense #2 Remote Location (192.168.2.0/24)
  4. Enter a Description
  5. Hit Save & Apply Changes
pfSense IPSec site to site
Creating a Firewall Rule

That’s it. We are done with pfSense #1 HQ, let’s head over to pfSense #2 Remote Location to create our pfSense site-to-site VPN.

Step 4 – Creating IPSec Phase 1 on pfSense #2 Remote Location

Now we basically need to repeat those exact steps again just with slightly changed values. I will guide you through every step anyway. Navigate to VPN / IPsec and click on + Add P1. Enter values as in the following:

  1. IP of your WAN Interface on your pfSense #1 HQ
  2. Enter a Description
pfSense IPSec site to site
Configuring Phase 1

Scroll down to Phase 1 Proposal (Authentication). Enter the same Pre-Shared Key like in pfSense #1 HQ that we created in Step 1.

pfSense IPSec site to site
Configuring Phase 1

Scroll to the bottom and hit Save & Apply Changes.

⚠️ If you would like to learn more about pfSense, I highly recommend you check out my pfSense Fundamentals Bootcamp over at Udemy. This is the most up-to-date as well as the highest-rated pfSense course on Udemy.

Step 5 – Creating IPSec Phase 2 on pfSense #2 Remote Location

Once again, click on +Show Phase 2 Entries and click on + Add P2.

pfSense IPSec site to site
Configuring Phase 2

Now enter values like in the following example:

  1. On Local network choose Network
  2. Enter the Subnet of your Local Network (192.168.2.0/24 for pfSense #2 Remote Location)
  3. On Remote Network choose Network
  4. Enter the Subnet of your Remote Network (192.168.1.0/24 for pfSense #1 HQ)

Enter a description if you want.

pfSense IPSec site to site
Configuring Phase 2

Scroll down to Phase 2 Proposal (SA/Key Exchange) and enter the values like below.

  1. Change AES Encryption to 256 bits
  2. Change PFS key group to 15 (3072 bit)
  3. Enter the pfSense #1 HQ’s IP Address to be pinged automatically (this ensures that the tunnel stays active at all times)
  4. Hit Save & Apply Changes.
pfSense site to site VPN
Configuring Phase 2

Step 6 – Creating a Firewall Rule on pfSense #2 Remote Location

Navigate to Firewall / Rules / IPsec. Click on Add. Enter values as the following:

  1. Change Protocol to Any
  2. For Source select Network
  3. Enter the Subnet of pfSense #1 HQ (192.168.1.0/24)
  4. Enter a Description
  5. Hit Save & Apply Changes
pfSense site to site VPN
Creating a Firewall Rule

Now, in theory, a tunnel should be established between the two.

Step 7 – Testing the Tunnel

Back on pfSense #1 HQ head to Status / IPsec. You should see, if everything went well, that a connection is established.

pfSense site to site VPN
Validating the Tunnel

You will see a similar picture on pfSense #2 Remote Location. We can do two more things to also validate if the firewall rules are correct: Running a Ping from a Client on each Firewall’s Subnet.

First I will try to Ping pfSense #1 HQ from a Client connected to pfSense #2 Remote Location.

pfSense site to site VPN
Running a Ping from pfSense #2 to pfSense #1

And now I run a Ping from a client connected to pfSense #1 HQ to pfSense #2 Remote Location.

pfSense site to site VPN
Ping from pfSense #1 to pfSense #2

Troubleshooting: pfSense Site to Site VPN Not Connecting

Your first stop is always Status, System Logs, IPsec on both firewalls. The log usually tells you which phase failed. Here’s what each symptom normally means:

SymptomLikely causeFix
Phase 1 never comes upDifferent pre-shared key, IKE version or Phase 1 proposalCompare both P1 entries field by field. Re-paste the key on both sides
Log shows “NO_PROPOSAL_CHOSEN”Encryption, hash or DH group don’t matchMake both sides match the settings table
Phase 1 up, Phase 2 downLocal and Remote Network are not mirroredSide A’s Local Network must be Side B’s Remote Network, and the other way round
Tunnel up, no trafficNo rule on the IPsec tabAdd the Firewall, Rules, IPsec rule on both sides
You can ping the firewall but not PCs behind itThe PC’s own firewall blocks other subnetsAllow the remote subnet on the host. Windows Firewall often blocks ping from other subnets by default
Nothing reaches the other side at allUDP 500/4500 or ESP blocked upstreamCheck ISP router port forwarding. Make sure “Disable all auto-added VPN rules” is off under System, Advanced, Firewall & NAT
Tunnel works, then drops every few hoursLifetime or dead peer detection mismatchMatch lifetimes on both sides, or set the responder side about 10 percent higher

One more that catches people: both LANs on 192.168.1.0/24. Two sites with the same subnet can’t route to each other over a plain tunnel. Change one LAN, it’s far less pain than NAT workarounds.

IPsec vs WireGuard vs OpenVPN for Site to Site

IPsec isn’t the only option on pfSense. Here’s how I’d choose:

IPsecWireGuardOpenVPN
Built inYesPackage (Package Manager)Yes
Works with other vendorsYes. Fortinet, Cisco, cloud VPN gatewaysOnly other WireGuard peersOnly other OpenVPN endpoints
Setup effortMedium. Many matching fieldsLow. Keys and peersMedium. Certificates
SpeedFast, especially with AES-NIFastSlower
Pick it whenThe other end isn’t pfSense, or you want the standardBoth ends run pfSense or Linux and you want simpleYou need TCP or a restrictive network in between

My default is still IPsec for site to site, because it talks to everything. If you’d rather go the OpenVPN route, I covered it in the pfSense OpenVPN guide.

FAQ

Do both sites need a static public IP?

It makes life easier. If one side has a dynamic IP, use a dynamic DNS hostname as the Remote Gateway on the other side, and consider making the dynamic side the one that starts the tunnel.

Can pfSense be behind another router for an IPsec tunnel?

Yes. pfSense uses NAT traversal automatically. Forward UDP 500 and UDP 4500 from the upstream router to pfSense’s WAN.

Can I connect more than two sites?

Yes. Add one Phase 1 per remote site on the main firewall, each with its own Phase 2 entries. For several WAN links on one box, see my pfSense multi-WAN guide.

Conclusion

Both pings go through, so the tunnel is up and the rules are right. That’s a working pfSense site to site VPN. Keep the settings table handy, because the next time a tunnel breaks, it’s almost always a mismatch between the two sides.

👀 This Tutorial has some related Articles!
👉 The Complete pfSense Fundamentals Bootcamp
👉 Install pfSense from USB – The Complete Guide
👉 Install pfSense on VirtualBox
👉 The Complete pfSense OpenVPN Guide
👉 The Complete pfSense DMZ Guide
👉 Generate SSL Certificates for HTTPS with pfSense
👉 The Complete pfSense Squid Proxy Guide (with ClamAV!)
👉 pfSense Site-to-Site VPN Guide
👉 pfSense Domain Overrides Made Easy
👉 pfSense Strict NAT (PS4,PS5,Xbox,PC) Solution
👉 The Best pfSense Hardware
👉 Traffic Shaping VOIP with pfSense
👉 pfSense OpenVPN on Linux – Setup Guide
👉 pfSense Firewall Rule Aliases Explained
👉 Email Notifications with pfSense
👉 pfSense DNS Server Guide

7 thoughts on “pfSense Site to Site VPN with IPsec: Step-by-Step Guide (2026)”

  1. hey man, need your help
    i have configured pfsense vpn/ipsec tunnel. ill explain my topology below and then tell you what i have done with pfsenses.
    i have two networks
    nat1->pfsense1->router1->mls1->pc1
    nat2->pfsense2->router2->mls2->pc2
    pfsense1-> wan=192.168.122.70 lan 192.1682.2
    router e0/0 connected to pfsense1= 192.168.2.1 e0/1 connected to mls1 =192.168.10.1
    mls1 e0/0 connected to router1 192.168.10.2 mls vlan 30 192.168.30.1
    pc1 192.168.30.30 all /24
    pfsense2 wan= 192.168.122.25 lan 192.168.3.3
    router2 e0/0 connected to pfsense2 192.168.3.1 e0/1 connected to mls 2 192.168.20.1
    mls2 e0/0 connected to router2 192.168.20.2 mls2 vlan 40 192.168.40.1
    pc2 192.168.40.40 all /24

    in my pfsense1-> vpn->ipsec->tunnel i have
    remote gateway 192.168.122.25 and AES 256bits SHA256 DH Group 14 (2048) and lifetime 3600
    and phase2
    local network 192.168.30.0 /24, remote network 192.168.40.0 /24
    firewall->rules->wan i have protocol any, source any, destination any
    another protocol tcp, source any, destination any and destination port IPsec NAT-T (4500)
    another protocol ESP, source any and destination any
    and another protocol UDP, source any, destination this firewall (self) and the destination port ISAKMP(500)
    firewall->rules->lan
    protocol any, source network 192.168.2.0 /24, destination any
    another protocol any, source network 192.168.30.0 /24 and destination any
    another protocol any, source 192.168.10.0 /24 and destination any
    firewall->rules->IPsec
    protocol any, source network 192.168.30.0 /24 and source network 192.168.40.0 /24
    another protocol any, source any, destination any

    Pfsense2
    in my pfsense2-> vpn->ipsec->tunnel i have
    remote gateway 192.168.122.70 and AES 256bits SHA256 DH Group 14 (2048) and lifetime 3600
    in phase2
    local network 192.168.40.0 /24, remote network 192.168.30.0 /24
    firewall->rules->wan i have protocol any, source any, destination any
    another protocol tcp, source any, destination any and destination port IPsec NAT-T (4500)
    another protocol ESP, source any and destination any
    and another protocol UDP, source any, destination this firewall (self) and the destination port ISAKMP(500)
    firewall->rules->lan
    protocol any, source network 192.168.3.0 /24, destination any
    another protocol any, source network 192.168.40.0 /24 and destination any
    another protocol any, source network 192.168.20.0 /24 and destination any
    firewall->rules->IPsec
    protocol any, source network 192.168.40.0 /24 and source network 192.168.30.0 /24
    another protocol any, source any, destination any

    Reply
  2. Same situation too :c I only see the gateway but i cant see my PC on the other site, can you resolve this?

    Reply

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Share via
Copy link
Powered by Social Snap