• Losing connection in ipsec phase 2 after 24 hours

    5
    0 Votes
    5 Posts
    3k Views
    T
    This issue has not reappeared in the last few days, and it used to occur at least once a day. The only major change to my configurations is to improve the stability of the PPPoE link to the Internet. I was using a USB Ethernet adapter for my PPPoE link and the link was quite unstable, typical PPPoE uptimes were a few hours max. I have since changed to a VLAN based solution to get my PPPoE traffic out of the pfsense environment. The result of this is that the PPPoE is now significantly more stable and at the same time the IPsec phase1 without phase 2 problem appears to have gone away. As well as being more stable the time to reconnect when the PPPoE link does fail has increased. With the USB Ethernet adapter the PPPoE Daemon would receive a TERM signal, shutdown, and then immediately reconnect. Now all the PPPoE outages look more like ISP issues and are loss of LCP echo, followed by a few attempts to reconnect. So the PPPoE link is down for a much longer time and does not instantly reconnect. So at this stage it looks like the IPsec loss of phase 2 may relate to the manner/frequency of link failure on the Internet link. I have left the IPsec links in IKEv1 and if the issue occurs again then I will hopefully be able to supply the appropriate logging information. Tim
  • 2.2.6-RELEASE IPSec & AWS VPN daily disconnects, multiple Phase-2

    2
    0 Votes
    2 Posts
    1k Views
    H
    How many phase 2 entries do you have? Make sure you're not running into https://forum.pfsense.org/index.php?topic=106260.msg592087#msg592087. Cheerio, Harry.
  • Ipsec error

    4
    0 Votes
    4 Posts
    4k Views
    M
    another error have been able to login with shrew vpn client soft but now no more access. error showing when login is negotiation timout occurred i have uninstall and reinstall still the same error. kindly help.
  • *FIXED* IPSec site-to-site transport mode GRE verification

    1
    0 Votes
    1 Posts
    938 Views
    No one has replied
  • After upgrading to 2.2.2\. IPsec not working.

    5
    0 Votes
    5 Posts
    9k Views
    L
    I had the same problem when upgrading from 2.1.5 to 2.2.6(chnging hardware and restoring the config etc.), in the end i needed to re-specify what interface the local endpoint of the phase1 entry, seems to have reset itself to the interface and not the virtual IP that was originally used. Hope this helps someone else.
  • User passwords for l2tp/ipsec

    1
    0 Votes
    1 Posts
    651 Views
    No one has replied
  • 2.3 L2TP/IPsec no l2tp interface

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    Read the warning note at the top of the wiki doc you linked – that won't work for Windows, for the exact case you have encountered.
  • IPSEC using VIP Alias (PPPoE) - PFSense 2.1

    2
    0 Votes
    2 Posts
    1k Views
    Z
    The only way I got it to work was to: Set up one pfSense gateway to connect to the internet via pppoe set up another pfSense as an IPSEC initiator and set up the IPSEC connection. Box (1) is my default gateway to the internet I route all traffic from (2) to (1) so that IPSEC box can route outwards to establish the IPSEC connection I set up a customer route from (1) to (2) for any traffic going to the remote site. PM me if you want more details.
  • IPSec and NAT

    2
    0 Votes
    2 Posts
    1k Views
    C
    That's the nature of how it works. Traffic matching the SPD is intercepted and sent across the IPsec if there is a matching SA. If the IPsec can't come up, it gets dropped. IPsec transport mode with a gif or GRE tunnel and a dynamic routing protocol is how failover is accomplished. Or policy routing though that's usually more complicated since you have to make sure routing on both ends is updated appropriately.
  • Any way to connect a Mac as mobile IPsec client?

    5
    0 Votes
    5 Posts
    4k Views
    -flo- 0-
    Yes, this page is a valuable resource also for other scenarios. It was the first reliable source I came across stating that the built in client from OS X should be working in this setup at all.
  • Pre Shared key for Site To Site and Mobile VPN

    1
    0 Votes
    1 Posts
    688 Views
    No one has replied
  • Site to site IPSec, pfSense 2.2.5 with IPCop 2.1.9

    1
    0 Votes
    1 Posts
    604 Views
    No one has replied
  • Upgrade from 2.2.6 to 2.3 broke mobile IPSec [fixed]

    10
    0 Votes
    10 Posts
    3k Views
    J
    Thanks makes total sense. thanks for your help
  • Improvement proposal IPSec IKEv2 - USERS in user manager - save EAP key

    4
    0 Votes
    4 Posts
    1k Views
    jimpJ
    No, they are not encrypted on disk. They're in the clear because they have to be for EAP to work properly with strongSwan (I misspoke and said mpd earlier, not sure where that came from…) https://doc.pfsense.org/index.php/Why_are_some_passwords_stored_in_plaintext_in_config.xml
  • IPSec Site-to-Site VPN it is possible to create a Remote Gateway group?

    1
    0 Votes
    1 Posts
    924 Views
    No one has replied
  • 0 Votes
    2 Posts
    932 Views
    C
    You have to add a P2 with the NAT in that case, otherwise it never enters enc0 to be translated and sent across.
  • 0 Votes
    5 Posts
    2k Views
    J
    I have the same problem. Can you share which NAT settings did you changed? Thanks
  • Ipsec tunnel to windows server 2012 R2

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Configure VPN / IPSec with a routed public IP

    1
    0 Votes
    1 Posts
    583 Views
    No one has replied
  • IKEv2 with EAP-MSCHAPv2 connected but no internet access (Resolved)

    3
    0 Votes
    3 Posts
    5k Views
    R
    Had similiar problem (0.0.0.0 route always added) when creating VPN from Windows GUI and PowerShell helped. Thanks.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.