• Scaling IPsec (and VPNs in general)

    Pinned
    2
    15 Votes
    2 Posts
    6k Views
    ?
    Thank you!
  • Upgrade from 2.7.2 to 2.8.0 ipsec

    Moved
    8
    0 Votes
    8 Posts
    196 Views
    C
    I definitely will do this next week and post here the results. Thank you
  • IPSec service won't start

    1
    0 Votes
    1 Posts
    20 Views
    No one has replied
  • Routed VTI Interface No Traffic On Other Side

    11
    0 Votes
    11 Posts
    177 Views
    planedropP
    Opened a Redmine about this since this either A. needs to be explained more clearly, or B. needs to be changed so the docs say "will" instead of "may". https://redmine.pfsense.org/issues/16340
  • Using VTI IPsec to bypass managed office NAT

    1
    0 Votes
    1 Posts
    32 Views
    No one has replied
  • [RESOLVED] IPSec tunnel OK but routers can't ping each others

    6
    0 Votes
    6 Posts
    15k Views
    A
    @nicolasfo said in [RESOLVED] IPSec tunnel OK but routers can't ping each others: You can know everything about everything thanks to Google. But if you don't know what to search, it is useless. The problem is resolved, by adding a bogus route, by hand. Here's the explanation : https://doc.pfsense.org/index.php/Why_can%27t_I_query_SNMP,_use_syslog,_NTP,_or_other_services_initiated_by_the_firewall_itself_over_IPsec_VPN Thanks for help Oh my god this worked! Created an account just to say THANK YOU for this. I have a pfSense<->Unifi connected via IPSec. Applying it on the pfSense side makes pfSense->Unifi direct gateway/FW connection possible. Applying it on the Unifi side made my IPSec work perfectly. Again, thank you!
  • Does not have a public address and is behind NAT

    4
    0 Votes
    4 Posts
    71 Views
    T
    @Gertjan said in Does not have a public address and is behind NAT: Managed to solve the problem. You need to enter any fictitious name and your external IP in DNS Resolver. I entered both my pfsense on one and the second pfsense.[image: 1753101520478-%D1%81%D0%BD%D0%B8%D0%BC%D0%BE%D0%BA-%D1%8D%D0%BA%D1%80%D0%B0%D0%BD%D0%B0-2025-07-21-%D0%B2-15.38.01.png] In phase 1 you need to register. [image: 1753101586516-%D1%81%D0%BD%D0%B8%D0%BC%D0%BE%D0%BA-%D1%8D%D0%BA%D1%80%D0%B0%D0%BD%D0%B0-2025-07-21-%D0%B2-15.39.32.png] After which everything started working.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    15 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    7 Views
    No one has replied
  • NAT via two PFSense Firewalls connected via IPSec

    4
    0 Votes
    4 Posts
    148 Views
    V
    @zulasch This would require, that you have defined an SPD for the "users" IP and the webserver in IPSec. But the clients IP is dynamic. So it would only work if you route the whole upstream traffic from the webserver over the VPN, which might not be what you want. It would work with any other kind of VPN though, which gives you the possibility to assign an interface to. Could be OpenVPN, Wireguard or IPSec VTI.
  • Pfsense Multi WAN IPSec Setup Issues

    1
    0 Votes
    1 Posts
    53 Views
    No one has replied
  • 0 Votes
    2 Posts
    409 Views
    GertjanG
    @Yamka said in TheGreenBow VPN Client issue with access through WAN with router in DMZ mode.: TheGreenBow VPN Client is this a VPN application on a device, the device is connected to the pfSense LAN ?
  • IPsec Tunnel - LAN can’t reach VPN clients

    1
    0 Votes
    1 Posts
    77 Views
    No one has replied
  • IPsec connection stops working upon large or fast data

    1
    0 Votes
    1 Posts
    64 Views
    No one has replied
  • IPSec Export: Apple Profile PHP error

    1
    0 Votes
    1 Posts
    56 Views
    No one has replied
  • Cannot go to Internet in IPSec Road Warrior tunnel

    1
    0 Votes
    1 Posts
    182 Views
    No one has replied
  • Turn off NAT-T in an IPSec Tunnel --

    5
    0 Votes
    5 Posts
    590 Views
    P
    @Phonebuff said in Turn off NAT-T in an IPSec Tunnel --: The connection is created and will stay active for hours, until I start doing something like a "netstat -rn", and then, while the session is up, the terminal becomes unresponsive until Putty fails with a Connection Error. Hoping someone has some ideas on where to start troubleshooting this so I can resolve the issue.
  • 0 Votes
    3 Posts
    414 Views
    G
    @viragomann Thank you for your response — I really appreciate you taking the time to help. However, I’ve already tested the exact scenario you're suggesting. Unfortunately, it didn’t work in my case. What I’m specifically looking for is feedback from someone who has successfully implemented Source NAT in a setup that matches my parameters, particularly: Site-A to Central-PF using IKEv2 Central-PF to Site-B using IKEv1 NAT at Central-PF, where Site-A is NATed to Central’s LAN IP before forwarding to Site-B I’m aware that when both IPsec tunnels use IKEv2, NAT works fine and there’s no need to configure BINAT or additional Phase 2 entries. However, in my situation — with mixed IKE versions — the NAT rule doesn’t appear to work as expected. If anyone has resolved this exact case or has real-world experience with this specific type of mixed IKE/IPsec/NAT scenario, I would greatly appreciate your insights. Thanks again!
  • 0 Votes
    2 Posts
    288 Views
    patient0P
    @dcugy I would update to the latest CE 2.8.0-RELEASE and report it when it happens again.
  • IPSec connections breaking or wireguard

    5
    0 Votes
    5 Posts
    530 Views
    O
    wanted to see if i could try pfsense+ edition which used to be free but for some reason i can't seem to find that key, isn't it free for home users anymore?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.