Here for Nuts & my future edification, if ever again necessary.
IPCop Box:
- Use pre-shared key
- Local and remote addresses thus: (a).(b).(c).0/255.255.255.0 where a b c is obviously the network
- Dead Peer detection set to restart
- IKE Encryption: Blowfish 256
- IKE Integrity: SHA and MD5
- IKE Grouptype: MODP 1536
- ESP Encryption: Blowfish 256
- ESP Integrity: SHA1 & MD5
- ESP Grouptype: Phase1 Group
- ESP Keylife: 8 hours
- IKE + ESP: Unchecked
- IKE Aggressive: Not checked
- PFS: Checked
- Negotiate Payload: Unchecked
pfSense Box:
- Local subnet: LAN subnet
- Remote subnet: (a).(b).(c).0 / 24
- Remote gateway (a).(b).(c).(d)
- Negotiation Mode: Main
- Indentifier: My IP Address
- Encryption Algo: Blowfish
- Hash Algo: SHA1
- DH Key Group: 5
- Lifetime - leave blank
- Authentication method: preshared-key
- Phase 2, Protocol: ESP
- Encryption Algo: Blowfish
- Hash Algos: SHA1 & MD5
- PFS Keygroup: 2
- Lifetime: 28800 Seconds
- Ping Host: This is redundant to the Dead Peer detection in IPCop, which will execute a restart
Add salt and pepper to taste, serve hot. Feeds 2.