---
description: Connect pfSense to Cloudflare WAN.
title: pfSense
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/cloudflare-wan/llms.txt  
> Use this file to discover all available pages before exploring further.

# pfSense

Last updated Aug 24, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/pfsense/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

This tutorial includes the steps required to configure IPsec tunnels to connect a pfSense firewall to Cloudflare WAN (formerly Magic WAN).

## Software tested

| Manufacturer | Firmware revision |
| --- | --- |
| pfSense | 24.03 |

## Prerequisites

This tutorial requires the following information:

- Anycast IP addresses (Cloudflare provides these)
- External IP addresses
- Internal IP address ranges
- Inside tunnel `/31` ranges

## Example scenario

This tutorial uses the following IP addresses. These examples replace legally routable IP addresses with IPv4 Address Blocks Reserved for Documentation ([RFC 5737 ↗](https://datatracker.ietf.org/doc/html/rfc5737)) addresses within the `203.0.113.0/24` subnet.

| Tunnel name | `PF_TUNNEL_01` | `PF_TUNNEL_02` |
| --- | --- | --- |
| Interface address | `10.252.2.26/31` | `10.252.2.28/31` |
| Customer endpoint | `203.0.113.254` | `203.0.113.254` |
| Cloudflare endpoint | `<YOUR_ANYCAST_IP_ADDRESS_1>` | `<YOUR_ANYCAST_IP_ADDRESS_2>` |
| pfSense IPsec Phase 2 Local IP | `10.252.2.27` | `10.252.2.29` |
| pfSense IPsec Phase 2 Remote IP | `10.252.2.26` | `10.252.2.28` |
| Cloudflare WAN static routes - Prefix | `10.1.100.0/24` | `10.1.100.0/24` |
| Cloudflare WAN static routes - Next hop | `PF_TUNNEL_01` | `PF_TUNNEL_02` |

## 1. Configure Cloudflare WAN IPsec tunnels

Use the Cloudflare dashboard or API to [configure two IPsec tunnels](https://developers.cloudflare.com/cloudflare-wan/configuration/how-to/configure-tunnel-endpoints/#add-tunnels). This guide uses the settings mentioned below for the IPsec tunnels throughout the remainder.

### Add IPsec tunnels

1. Follow the [Add tunnels](https://developers.cloudflare.com/cloudflare-wan/configuration/how-to/configure-tunnel-endpoints/#add-tunnels) instructions to create the required IPsec tunnels with the following options:
   - **Tunnel name**: `PF_TUNNEL_01`
   - **Interface address**: `10.252.2.26/31`
   - **Customer endpoint**: `203.0.113.254`
   - **Cloudflare endpoint**: Enter one of the anycast IP addresses assigned to your account, available in [Leased IPs ↗](https://dash.cloudflare.com/?to=/:account/ip-addresses/address-space).
   - **Health check rate**: *Medium*
   - **Health check type**: *Request*
   - **Health check direction**: *Bidirectional*
   - **Turn on replay protection**: Enable
2. Select **Add pre-shared key later** > **Add tunnels**.
3. Repeat the process to create a second IPsec tunnel with the following options:
   - **Tunnel name**: `PF_TUNNEL_02`
   - **Interface address**: `10.252.2.28/31`
   - **Customer endpoint**: `203.0.113.254`
   - **Cloudflare endpoint**: Enter the second anycast IP address assigned to your account.
   - **Health check rate**: *Medium*
   - **Health check type**: *Request*
   - **Health check direction**: *Bidirectional*
   - **Turn on replay protection**: Enable
4. Select **Add pre-shared key later** > **Add tunnels**.

Note

If site-to-site traffic is a requirement, enable replay protection. Refer to [Add tunnels](https://developers.cloudflare.com/cloudflare-wan/configuration/how-to/configure-tunnel-endpoints/#add-tunnels) > IPsec tunnel to learn how to enable this feature.

### Generate pre-shared keys

When creating IPsec tunnels with the option **Add pre-shared key later**, the Cloudflare dashboard will show a warning indicator.

1. Select **Edit** to edit the properties of each IPsec tunnel.
2. Select **Generate a new pre-shared key** > **Update and generate pre-shared key**.
3. Copy the pre-shared key value for each IPsec tunnel, and save these values. Then, select **Done**.

Note

Take note of the pre-shared keys to use later in pfSense.

### IPsec identifier - User ID

After creating IPsec tunnels, the Cloudflare dashboard will list them under **Tunnels**. To retrieve the IPsec tunnel's user ID:

1. Go to the **Connectors** page.

[Go to **Connectors** ↗](https://dash.cloudflare.com/?to=/:account/magic-networks/connections)

2. In the **IPsec/GRE tunnels** tab, select the IPsec tunnel.
3. Scroll to **User ID** and copy the string. For example, `ipsec@long_string_of_letters_and_numbers`.

Configuring IKE Phase 1 on the pfSense firewall requires the User ID.

## 2. Create Cloudflare WAN static routes

Create a [static route](https://developers.cloudflare.com/cloudflare-wan/configuration/how-to/configure-routes/#create-a-static-route) for each of the two IPsec tunnels configured in the previous section, with the following settings (settings not mentioned here can be left with their default values):

### Tunnel 01

- **Description**: `PF_TUNNEL_01`
- **Prefix**: `10.1.100.0/24`
- **Tunnel/Next hop**: `PF_TUNNEL_01`

### Tunnel 02

- **Description**: `PF_TUNNEL_02`
- **Prefix**: `10.1.100.0/24`
- **Tunnel/Next hop**: `PF_TUNNEL_02`

## 3. Configure the pfSense firewall

Install pfSense and boot up. Then, assign and set LAN and WAN interfaces, as well as IP addresses. For example:

- **LAN**: `203.0.113.254`
- **WAN**: `<YOUR_WAN_ADDRESS>`

### Configure IPsec Phase 1

Add a new IPsec tunnel [Phase 1 entry ↗](https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/configure-p1.html), with the following settings:

- **General Information**
  - **Description**: `CF1_IPsec_P1`
- **IKE Endpoint Configuration**
  - **Key exchange version**: *IKE\_v2*
  - **Internet Protocol**: *IPv4*
  - **Interface**: *WAN*
  - **Remote gateway**: Enter the Cloudflare Anycast IP address.
- **Phase 1 Proposal (Authentication)**
  - **Authentication method**: *Mutual PSK*
  - **My identifier**: *User Fully qualified domain name* > `ipsec@long_string_of_letters_and_numbers`   
     (Find this identifier in the Cloudflare IPsec tunnel configuration > **User ID**)
  - **Peer identifier**: *Peer IP Address* (Cloudflare Anycast IP)
  - **Pre-Shared Key (PSK)**: Enter the pre-shared key from the Cloudflare IPsec tunnel.
- **Phase 1 proposal (Encryption algorithm)**
  - **Encryption algorithm**: *AES 256 bits*
  - **Key length**: *256 bits*
  - **Hash algorithm**: *SHA256*
  - **DH key group**: *20*
  - **Lifetime**: `86400`

### Configure IPsec Phase 2

Add a new IPsec tunnel [Phase 2 entry ↗](https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/configure-p2.html), with the following settings. Create two separate Phase 2 entries (one for tunnel 1 and one for tunnel 2), adjusting the IP addresses for local and remote networks accordingly:

- **General Information**
  - **Description**: `CF1_IPsec_P2`
  - **Mode**: *Routed (VTI)* (Virtual Tunnel Interface)
- **Networks**
  - **Local Network**: *Address* > Higher IP address in the `/31` assigned in Cloudflare tunnel. For example, `10.252.2.27` for tunnel 1 and `10.252.2.29` for tunnel 2.
  - **Remote Network**: *Address* > Lower IP address in the `/31` for Cloudflare side. For example, `10.252.2.26` for tunnel 1, and `10.252.2.28` for tunnel 2.
- **Phase 2 Proposal (SA/Key Exchange)**
  - **Protocol**: *ESP* (Encapsulating Security Payload)
  - **Encryption algorithm**: *AES 256 bits*
  - **Hash algorithm**: *SHA256*
  - **DH key group**: *20*
  - **Lifetime**: `28800`

Apply the changes. Navigate to **Status** > **IPsec** to verify that both Phase 1 and Phase 2 are connected.

![pfSense IPsec overview](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1999,height=931,format=webp/_astro/ipsec-overview.B7tL0kto.png)

### Interface assignments

In **Interfaces** > **Assignments** > **Add**, create a new interface to assign to the first IPsec tunnel, with the following settings:

- **General configuration**
  - **Description**: `CF1_IPsec_1`
  - **MSS**: `1446`
- **Interface Assignments**
  - **WAN**: Add the WAN interface. For example, `vnet1`.
  - **LAN**: Add the LAN interface. For example, `vnet0`.
  - Add the **CF\_IPsec\_1** interface from Phase 1 above.

Select **Save** to apply the changes.

![Assign a new interface to the first IPsec tunnel](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1999,height=1317,format=webp/_astro/interfaces.COkbEEZi.png)

![Configuring interface assignments](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1999,height=814,format=webp/_astro/interface-assignments.CblqhRKO.png)

### Gateway

In **System** > **Routing** > **Gateways** there should already be a gateway. For this example, it is named `CF1_IPSEC_1_VTIV4`.

![There should already be a gateway configured in the interface](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1999,height=1013,format=webp/_astro/gateways.BWYSJrzk.png)

### Firewall Rules IPsec

1. In **Firewall Rules** > **IPsec interface**, allow any type of traffic.

![Allow all traffic for IPsec](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1999,height=617,format=webp/_astro/firewall-ipsec.CgXaJWLX.png)

2. Navigate to **Status** > **Gateways**. `CF1_IPSEC_1_VTIV4` should now be online.

![The gateway should now be online](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1999,height=630,format=webp/_astro/status-gateways.CAqgLr_K.png)

### Firewall Rules LAN

1. In **Firewall** > **Rules** > **LAN**, allow any type of traffic.
2. Expand the **Advanced** section.
3. Change the Gateway to `CF1_IPSEC_1_VTIV4`.

![Change the gateway in the firewall rules for LAN traffic](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1999,height=753,format=webp/_astro/firewall-lan.DduZnf_o.png)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/pfsense/#page","headline":"pfSense · Cloudflare WAN docs","description":"Connect pfSense to Cloudflare WAN.","url":"https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/pfsense/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-08-24","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```
