• IPSEC between 2x pfsense

    8
    0 Votes
    8 Posts
    1k Views
    B
    Thnx for the tip. For now I can ping to both sides (network devices like AP's). i am still not able to ping windows hosts on the remote side. it looks like this problem: https://superuser.com/questions/1087392/windows-firewall-blocking-ssh-to-secondary-subnet?noredirect=1&lq=1 The windows firewall is disabled. To be sure i've added the any to any rule but without success. The ping is arriving on the remote side (LAN interface) but i think windows is not responding because the traffic comes from an different subnet. isn't it easier to translate the traffic to the local subnet on both sides?
  • Pfsense 2.4.3 ipsec.conf is not updated

    6
    0 Votes
    6 Posts
    2k Views
    B
    Of Course you right it is totally my mistake :) it should be in WAN2 ….. thanks a billion.
  • Slow traffic over IPsec tunnel after a move but public traffic still fast

    13
    0 Votes
    13 Posts
    3k Views
    S
    Well….I'm at a loss. I'm now testing from hosts behind pfSense (vs between pfSense boxes themselves). I thought I had a breakthrough when I found aes-ni disabled in Advanced but realized that was a troubleshooting tip here :) MTU is back to defaults, no MSS clamping, using IKE2.... Both boxes also have OpenVPN tunnels to other boxes but the average load is like 1mbs. Without the tunnel, I easily get 230-250mbs. With the tunnel (and new since my original post gig wan line) I get 30-50mbs. Xeon on one side* and SH-4860 on the other. Neither CPU spikes above 30-40%. I tried recreating the P1 and P2 tunnels - no change. I failed to mention... the Xeon is pfSense running as a VM on Proxmox 5. It's the only VM, the CPU type is host, it has 16gb of ram allocated and direct disk access. So it's basically as close to the bare metal as it can be. But if anyone has any tips related to Prox and aes performance, lay em on me!
  • IPsec client from Bogon network

    1
    0 Votes
    1 Posts
    361 Views
    No one has replied
  • IPsec GCP setup

    1
    0 Votes
    1 Posts
    783 Views
    No one has replied
  • Problems with VPN IPSEC rules not working

    3
    0 Votes
    3 Posts
    814 Views
    G
    I don't think the logs you posted are relevant to your issue, they seem to be discarded packets for expired connections or something else. What side are you attempting to connect to and from? I didn't get that clear. The rules on your pfSense local side look fine. If you are trying to connect from the local side to the remote and it fails, it may be a misconfig on the Fortinet side
  • Ipsec routing from branch to central then internet driving me crazy

    2
    0 Votes
    2 Posts
    394 Views
    G
    IPsec policies have routing preference over everything on the system (pretty much). If you create a tunnel with destination 0.0.0.0/0, the tunnel goes up and something is misconfigured, I guess you wouldn't get internet access at all instead of getting routed through the regular WAN. Post your detailed configuration
  • Connect 2 clients from LAN to L2TP/IPSec server simultaneously

    1
    0 Votes
    1 Posts
    362 Views
    No one has replied
  • IOS 11.3 Clients Broken But MacOS Clients Work

    9
    0 Votes
    9 Posts
    1k Views
    jimpJ
    @PhYrE: DH group 5 and group 14 was tested as well but is not recommended. Commentary on the DH groups is provided by:   https://supportforums.cisco.com/t5/security-documents/diffie-hellman-groups/ta-p/3147010 This chart from strongSwan is a bit more informative and has better info than that post: https://wiki.strongswan.org/projects/strongswan/wiki/IKEv2CipherSuites#Diffie-Hellman-Groups
  • IPSec traffic stops, no errors, but link stays up

    4
    0 Votes
    4 Posts
    968 Views
    lifeboyL
    @dotdash: Check the other side and verify all the settings match. Verify the phase two ID's match. The connection is established and stays established for phase 1 and 2.  If there was a mismatch, they wouldn't connect to begin with.  I have checked both sides many times and everything matches. The link stays up, but if nothing is done over it, something happens that puts the link into a state where no traffic traverses over it.  Then, by attempting to connect to a database service on the other end, the link is woken up after about 30 - 60 seconds.
  • IPsec multi-wan failover

    40
    0 Votes
    40 Posts
    40k Views
    F
    Well, i'm one more with the same problem. First of all, PFsense 2.4.2, both sides with Group Gateway Failover, DDNS on Remote Gateway. So, i'm reading a lot of articles and, … i'll test a single change at IPSEC configuration. VPN > IPSEC > Advanced Configuration > Configure Unique IDs as NO. Why ? https://blog.bravi.org/?p=1209 I don't know if i misunderstood, but, i'll try this shot …
  • 2.4.3 iOS Client Fails on AES-NI Active, but Works with AES Off

    2
    0 Votes
    2 Posts
    484 Views
    S
    Switched to IKEv2, set AES-NI CPU Crypto: Yes (active) and all is good. Encryption: IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/ECP_384
  • IPSec Tunnel unstable 2.3.3-release-p1

    9
    0 Votes
    9 Posts
    2k Views
    N
    @GroundX: Upgraded to 2.3.4 still the same but under other settings: Have this as well when IPSec turns instable/flapping. P2 seems stable but not P1. Apr  3 16:34:45 FWstockholm charon: 07[KNL] <con1|19533>unable to query SAD entry with SPI cb9b98b3: No such file or directory (2) Apr  3 16:34:47 FWstockholm charon: 10[KNL] <con1|19533>unable to query SAD entry with SPI cf573dd5: No such file or directory (2) Apr  3 16:34:47 FWstockholm charon: 10[KNL] <con1|19533>unable to query SAD entry with SPI cb9b98b3: No such file or directory (2) Apr  3 16:34:49 FWstockholm charon: 15[KNL] <con1|19533>unable to query SAD entry with SPI cf573dd5: No such file or directory (2) Apr  3 16:34:49 FWstockholm charon: 15[KNL] <con1|19533>unable to query SAD entry with SPI cb9b98b3: No such file or directory (2) Apr  3 16:34:50 FWstockholm charon: 13[KNL] <con1|19533>unable to query SAD entry with SPI cf573dd5: No such file or directory (2) Apr  3 16:34:50 FWstockholm charon: 13[KNL] <con1|19533>unable to query SAD entry with SPI cb9b98b3: No such file or directory (2) Apr  3 16:34:55 FWstockholm charon: 10[KNL] <con1|19533>unable to query SAD entry with SPI cf573dd5: No such file or directory (2) Apr  3 16:34:55 FWstockholm charon: 10[KNL] <con1|19533>unable to query SAD entry with SPI cb9b98b3: No such file or directory (2) This to a Cisco ASA with IKEv2. Have two tunnels on the specific pfSense firewall, one to the above Cisco ASA and another one to a pfSense-box. The last one is solid!</con1|19533></con1|19533></con1|19533></con1|19533></con1|19533></con1|19533></con1|19533></con1|19533></con1|19533> 2.3.4 is stable or not?
  • View status causes "unable to query SAD entry" in log

    6
    0 Votes
    6 Posts
    6k Views
    N
    @jcasanellas: Hello I have the same problem, but only with a tunnel I have 6 running and only one fails me. Attachment capture error. I hope your answer Thank you That devices on the other side?
  • Can connect on VPN server, but no internet access.

    4
    0 Votes
    4 Posts
    4k Views
    R
    UDP is needed for DNS lookup. Easiest to just set it for any (if your IPSEC clients are trusted of course)
  • Some protocol don't go through my IPSec VPN tunnel

    2
    0 Votes
    2 Posts
    436 Views
    J
    Can you please provide any screenshots of logs and can you please provide the configs that you have done for p1 and p2 of IPSEC Tab. Just the HTTPS traffic are not working?
  • IPSec Tunnel and VoIP

    7
    0 Votes
    7 Posts
    1k Views
    J
    Did you already create a port forward rule on wan that opens UDP Port 5060-5080 and RTP port 10000 - 20000? It is required for the VOIP to work on. Also I noticed that subnet of your LAN and WAN that you have configured for your pfsense is the same subnet. Did you already tried to change the network of your LAN? Try to make it 172.xx.xx.xx or any private IP Address that is different from your WAN Subnet. Hope this can help you
  • Is it possible to create a remote to site vpn with pfsense and zywall?

    1
    0 Votes
    1 Posts
    276 Views
    No one has replied
  • Problem on VOIP on Site to Site VPN between Pfsense and Sonicwall

    5
    0 Votes
    5 Posts
    1k Views
    J
    Hi Hoe, Please be inform that my issues has been resolved now. I have do the following methods. 1. Change the Firewall Optimization Options to "Conservative" on System > Advanced > Firewall & NAT (PFsense Side) 2. "Unchecked" the Clean Up Active tunnels when Peer Gateway DNS name resolved to different IP Address (Sonicwall Side) 3. Unchecked everything except for "Enable Keep Alive" on the advanced settings of the vpn setup on Sonicwall. Please refer on the attached screenshot as reference. [image: 1.png] [image: 1.png_thumb] [image: 2.png] [image: 2.png_thumb] [image: 3.png] [image: 3.png_thumb]
  • IPsec VPN problems with AES128 and strongSwan VPN Client

    3
    0 Votes
    3 Posts
    1k Views
    L
    For the details of the Windows VPN Client settings have a look here: https://wiki.strongswan.org/projects/strongswan/wiki/Windows7
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.