• VPN Phase 2 Entry For Static Routed Network

    1
    0 Votes
    1 Posts
    352 Views
    No one has replied
  • IPSEC Route all but local traffic

    14
    0 Votes
    14 Posts
    2k Views
    O
    got it fixed.  missing nat rule on PFA from internet to 10.253.253.0/24 network
  • IPSec VPN to Softether Server

    12
    0 Votes
    12 Posts
    3k Views
    E
    Problem solved! Now i can connect my pfsense box as a client to my SoftEther server. The problem was the latest (RTM) Version of SoftEther server, which seems to have an issue with OpenVPN. After installing an earlier version, everything is working as expected.
  • Quick question

    5
    0 Votes
    5 Posts
    757 Views
    P
    @Derelict: Probably no and not that I know of. Make your IPsec connection from behind the firewall or use an OpenVPN provider. Thank you, I'll do that.
  • 0 Votes
    1 Posts
    372 Views
    No one has replied
  • IPsec from Azure pfSense VPN appliance to on-premises box

    1
    0 Votes
    1 Posts
    405 Views
    No one has replied
  • USG - pfsense IPsec VPN

    3
    0 Votes
    3 Posts
    3k Views
    N
    jcconnell did you ever get this resolved? I am having the the same issue as you are having and all my networks are setup properly. Let me know!
  • IPsec performance

    Locked
    3
    0 Votes
    3 Posts
    673 Views
    M
    Sometimes you have good days, and sometimes bad ones. This is a bad day; I have been toying around too much around data centers and totally forgot my home internet wasn't quite as symetrically performant (faster download of course) I'll show myself out (and lock this thread)
  • Ipsec Site to SITE VPN issue with mulitple scopes

    2
    0 Votes
    2 Posts
    495 Views
    M
    Hello on your phase 2 entire do you have 192.168.2.0/24 and 192.168.3.0/24 setup? or are you doing 192.168.0.0/16? Thanks
  • Pfsense IPSEC tunnel to redundant endpoints

    3
    0 Votes
    3 Posts
    2k Views
    C
    Sorry for delay! So I tested it on my end, the 2 tunnel goes up, but if I unplug one of my remote WAN port, the tunnel doesn'T switch to the other one (even if the tunnel is up…) I configure the DPD (dead peer detection), 5 sec for 5 poll, to disconnect the tunnel, it doesn't work... I am not sure if it is possible.. I guess the only way would be to setup a DynDNS or NO-IP on the remote firewall so they can update the IP between the active ISP. But IMO, it is not a good solution for a large enterprise, as in my experience, for me, SOnicwall and DynDNS is scrap, no-ip works okay but I do prefer using a direct IP
  • Disable Scrubbing on IPSEC interface only

    2
    0 Votes
    2 Posts
    1k Views
    L
    Looks like others are affected too : https://redmine.pfsense.org/issues/7801 Any chance to get fragmented UDP across IPSEC Tunnels with pfSense??
  • IPSec just won't connect, pulling my hair

    4
    0 Votes
    4 Posts
    717 Views
    DerelictD
    I don't think there is any reason for the P1 to even attempt a connection without a P2. There is no interesting traffic in that case. There are no connection attempts in the logs you posted. I would config a P2 and try again.
  • Access LDAP from WAN through IPSec- Site-to-site

    3
    0 Votes
    3 Posts
    502 Views
    C
    The lookups are sourced from Virt.Publ.IP because I have only one Publ.IP on IPSec-Site2 and the Ports are already in use (and I cant Change!). On Site1 I have several Publ.IP-Adresses free to use. I put the Settings of the document, but not successful. Checked Tunnel again and ist working fine in both directions. Is there anybody who did something like that already?
  • IPSEC VPN from HA pfSense to AWS VPC instance not routing

    4
    0 Votes
    4 Posts
    1k Views
    DerelictD
    You need to route the correct traffic from the VPC to the VGW in AWS. Traffic from the pfSense side is sent to the VPN according to the traffic selectors (phase 2 networks).
  • Which VPN Authentification?

    5
    0 Votes
    5 Posts
    726 Views
    A
    Hello Got it to work. :) EAP-Radius means that the VPN Server will send the Authentification to the FreeRadius Server (That was not clear for me). So i can use now EAP-TLS and EAP-MSCHAPV2 with Freeradius at the same Time. Thanks Regards Alitai
  • IPSec stops working after a while until pfsense reboot

    1
    0 Votes
    1 Posts
    308 Views
    No one has replied
  • 0 Votes
    2 Posts
    579 Views
    J
    Sorry to dig up an old post, but I was wondering if you ever found a solution? I have have an ongoing problem very similar to yours and like you discovered, it only seems to affect my systems that are running 2.4.2 or later. Link to previously created thread. https://forum.pfsense.org/index.php?topic=143728.0
  • 0 Votes
    2 Posts
    679 Views
    Y
    It seems to be a regular win10 IPv6 VPN client problem. Maybe it should be solved by using link-local addresses on IPsec interface. For now I have solved the problem by creating a power shell script to create a windows VPN connection definition. The script adds route ::/0->:: Add-VpnConnectionRoute -ConnectionName $connection_name -DestinationPrefix ::/1 Add-VpnConnectionRoute -ConnectionName $connection_name -DestinationPrefix 8000::/1 The Add-VpnConnectionRoute cmdlet does not allow to manipulate with ::/0 , this is why there are two routes, for ::/1 and for 8000::/1 And how are you, who already uses IPsec on IPv6, working with client routes? Are they automatically created? Do you use link-local addresses on IPsec interface?
  • IPSEC Site to Site VPN

    13
    0 Votes
    13 Posts
    1k Views
    M
    Its ok I figured it out…didn't have the correct rule on the IPSec Rules for the firewall...all good now thanks
  • IPSEC Tunnel to WIN10 behind NAT driving me crazy

    3
    0 Votes
    3 Posts
    643 Views
    L
    Double check that you are using IKEv2 on both ends. This looks like IKEv1 with UDP Port 500 : Mar 5 16:36:52 charon 16[NET] <1> sending packet: from 78.94.x.x[500] to 80.187.96.197[500] (337 bytes)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.