• IPSec Routing stops working??

    4
    1 Votes
    4 Posts
    779 Views
    J
    Update: I've upgraded to 2.4.3-RELEASE-p1 switched back to IPSec from OpenVPN and haven't experienced the issue ~72hrs and counting.
  • RSA ipsec : no private key found...

    3
    0 Votes
    3 Posts
    4k Views
    A
    Yes you are right, it works now! (in fact, in the meantime, I tried using PSK auth, and same issue with bad identifiers but error messages were more relevant for me). solution for anyone who would have this issue => use altNames values of certificates (get it with "ipsec listcerts" command) in the leftid/rightid strongswan's tunnel parameters. Thanks for your reply.
  • key_acqdone / key_delete

    Moved
    3
    0 Votes
    3 Posts
    643 Views
    R
    yes site 2 site vpn with ipsec
  • IPSEC to CradlePoint...Tunnel Established But No Ping

    17
    0 Votes
    17 Posts
    3k Views
    DerelictD
    Glad you got it working. Thanks for letting us know.
  • IPSec VLAN Passthrough

    1
    0 Votes
    1 Posts
    502 Views
    No one has replied
  • Can't seem to get pfSense to stay connected to IPCop firewall

    3
    0 Votes
    3 Posts
    685 Views
    DerelictD
    We can get the VPN to connect for a little while but we can't ping through it even though we have a Firewall rule set for IPSec. Firewall rules on the IPsec tab would be for allowing pings originating from the other side. Be sure you are pinging from something interesting to IPsec, as in from a source address that is in the Local Network portion of a phase 2. You can set a source interface to something like LAN if you're using Diagnostics > Ping.
  • IPSEC VPN Drops around 40 seconds.

    5
    0 Votes
    5 Posts
    956 Views
    jimpJ
    What do the logs on the Draytek say? pfSense can't tell you why the Draytek sent the delete command, only the Draytek can.
  • IPSec site to site VPN "Connecting" Status only

    1
    0 Votes
    1 Posts
    236 Views
    No one has replied
  • Route IPSEC

    2
    0 Votes
    2 Posts
    385 Views
    jimpJ
    IPsec tunnels don't "route"¹ , they use Phase 2 definitions to setup Security Associations that define which traffic will be able to cross each tunnel. So you need to add Phase 2 entries to both ends of every tunnel to match every combination of traffic you hope to send across the tunnel. So if you have tunnels A-B and A-C, you need phase 2 entries on A-B to pass traffic from B-C and on A-C to pass C-B and vice versa. ¹ well, until 2.4.4 and they have to support VTI
  • [GUIDE] IKEv2/IPSec, Per user firewall rule settings with FreeRADIUS

    2
    2 Votes
    2 Posts
    4k Views
    L
    @pfbest This is amazing! Thank you so much, it works really well.
  • IPSEC over LDAP (Synology AD)

    1
    0 Votes
    1 Posts
    359 Views
    No one has replied
  • ipsec

    2
    0 Votes
    2 Posts
    351 Views
    U
    @utilizador_estagio I created an user and installed that user certificate in my machine...but it wont work. what else can i do ?
  • Fortigate and PFSENSE...

    3
    0 Votes
    3 Posts
    1k Views
    A
    Hello and thanks for your answer. In fact, we saw some posts on the net with this log, pointing to a psk mismatch. We made a lot (LOT) of tests with a lot of different PSK, the P1 never got up. we tried some '1234', 'test', and so on, psk's ...
  • IKEv2 EAP-RADIUS + group authentication

    1
    0 Votes
    1 Posts
    327 Views
    No one has replied
  • [IPSec] VPN with Multi Subnets

    11
    0 Votes
    11 Posts
    1k Views
    R
    @dave-opc said in [IPSec] VPN with Multi Subnets: It is possible, and it will not be with the same configuration On Company2 you create 1st P2 with local 172.16.0.0 and remote 172.16.10.0 and create 2nd P2 with local 172.16.0.0 and remote 172.16.4.0 On Company1 you create 1st P2 with local 172.16.4.0 and remote 172.16.0.0 and create 2nd P2 with local 172.16.10.0 and remote 172.16.0.0 I had tried this, but I was forgetting to change the output interface of Company 1, that is, I was making a faithful copy of the existing P2, a lot of my attention, thank you for helping me.
  • Pfsense on AWS IPsec

    3
    0 Votes
    3 Posts
    595 Views
    T
    security group Elastic IP: All Traffic Searching the internet, I did not find anything related to pfsense in AWS providing VPN ipsec . [image: 1532344838279-screenshot-sa-east-1.console.aws.amazon.com-2018.07.23-08-19-33-resized.png]
  • Cannot get mobile IPSEC client to route over IPSec site-to-site tunnel

    11
    0 Votes
    11 Posts
    1k Views
    M
    Bingo! That did the trick. Thank you :)
  • 1:1 Nat over IPSec - no networks found

    2
    0 Votes
    2 Posts
    473 Views
    P
    Figured it out! It was a mixup on the ip's configured in the Phase 2 network settings, when using the BiNat feature.
  • 0 Votes
    3 Posts
    614 Views
    R
    @nogbadthebad said in IPSEC VPN between 2 sites has constant ~20k traffic. How best to find out what it is?: Have you tried a packet capture ? I didn't realize pfSense had a packet capture. Thanks for suggesting it. Now the results. I ran a quick capture on ipsec and then found the busy ip address. A quick look at the lease assignments showed me it was my Uniden Police Scanner wifi dongle. Then it hit me. I run Proscan scanner software from my office that points to my Uniden scanner to capture fire calls in my town (using the "fire tone out" feature), and then email them to me so I can hear them on my phone. I totally forgot that I had that communication running all the time, but the packet capture quickly pointed it out. Problem solved. Thanks for the tip. Roveer
  • 0 Votes
    11 Posts
    2k Views
    H
    @dkase279 mine prevents the tunnel from working as client machines can not ping through to my main site via the VPN. I'm going to log a call with Netgate if possible as it's preventing service. I also might put logs on here once it happens again.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.