• IPSEC initiation from one side only

    8
    0 Votes
    8 Posts
    2k Views
    C
    Config can differ as initiator vs. responder. UDP 500 traffic could be blocked in that direction but not the opposite. Regardless you need to look at the Juniper side and see why it's not replying.
  • P2 problems pfSense <-> Juniper

    2
    0 Votes
    2 Posts
    1k Views
    C
    The Juniper is first not replying, and second, sending a delete. No way to tell anything useful from that side's logs in that case, check the logs on the Juniper side.
  • IPSEC address to address

    1
    0 Votes
    1 Posts
    807 Views
    No one has replied
  • Phase 1 problem after phase 1 lifetime ends

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Insight into ipsec traffic

    1
    0 Votes
    1 Posts
    573 Views
    No one has replied
  • Client VPN and then Site to Site VPN traversal (possible?)

    3
    0 Votes
    3 Posts
    1k Views
    K
    I am trying to do the same but confused as to your explanation.  Any screenshots would be great!
  • IPSEC widget error

    14
    0 Votes
    14 Posts
    4k Views
    M
    2.3 is not affected :)
  • L2TP, Privat Network -> Public Network

    2
    0 Votes
    2 Posts
    765 Views
    J
    Seems like pfSense auto adds a NAT rule (default "Automatic outbound" is selected in Outbound "Firewall: NAT: Outbound"). I changed Outbound to "Hybrid outbound", and added an exception "Do not NAT" with the subnet used for L2TP; see attachment. Image is manipulated to mask my real IP/mask, instead using 8.8.8.0/29 as the example in my previous post. [image: outbound.png_thumb] [image: outbound.png]
  • Bounty offered: IKEv2 for iOS and OSX mobile client

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    M
    Ok, my solution is posted to a new post, to keep things clean. https://forum.pfsense.org/index.php?topic=106433.0 Imagine how pleased I was to find that the forum does not support markdown and I had to reformat the whole thing!!! It would be great if that post could be 'stickied' if this forum supports that, at least for as long as the instructions are valid!
  • No traffic over ipsec

    4
    0 Votes
    4 Posts
    1k Views
    2
    IPsec tunnels need NSA/GCHQ approval before coming functional, I had that several times in the past. openVPN the apparently crack on-the-fly, so they "work" out of the box… ;-)
  • IPSEC Tunnels / Routing in between

    8
    0 Votes
    8 Posts
    2k Views
    G
    Sorry, my bad. I did this several times but the "branches" were in fact OpenVPN tunnels, and they were connected through an IPsec tunnel between the main sites. On the basis of how all this work, I don't think you can do what I mentioned earlier (although I never tried) Probably your best bet is to use some dynamic DNS so you can establish a direct Ph1 between the branches, since you'll be able to ditch the 0.0.0.0/0 requirement
  • Site-to-Site + Synology Diskstation = Problems

    2
    0 Votes
    2 Posts
    2k Views
    S
    The plot thickens a bit more and I get more and more out of my depth of field. I have toggled the following value: net.inet.ip.redirect = 0 (default 1) and communication between the Diskstation and Azure has been restored. Have I set myself up for more problems by altering the above flag? Thanks in advance!
  • Forcing all traffic over IPSec VPN and the ability to do further routing

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    You can't "route" it in the traditional way but depending on what you're trying to do, it may still be possible. It's all up to the Phase 2 networks in IPsec. You can force all traffic over the tunnel from the LAN (local P2 net = LAN network, remote P2 net = 0.0.0.0/0) but that means everything from the LAN will be forced over IPsec. Once it hits the other side you'll have to pass it in the rules, NAT it outbound, etc.
  • IPSec Behind Nat

    2
    0 Votes
    2 Posts
    2k Views
    dotdashD
    I believe your real subnet must match your binat subnet. Try making your local subnet 172.16.10.1 or something to match.
  • 0 Votes
    2 Posts
    747 Views
    E
    Update. I updated the firmware this broke it completely. So I removed the vpn config and added it back in and this worked again. with the same results. add a new user and it brakes. any ideas?
  • Windows can't connect pfsense ipsec ikev2 if src and dst both pfsense.

    3
    0 Votes
    3 Posts
    1k Views
    S
    I have two different sites with pfsense. At my place I have also pfsense. Trying to connect with ipsec vpn as a client to either site always results in error 809 All 3 places have simple one lan setups
  • IPSec VPN Dropping / Reconnect Issues

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • IPsec site-to-site 80% slower than max speed

    13
    0 Votes
    13 Posts
    19k Views
    J
    @jamesbond: I also have a very similar problem with slow traffic over IPsec tunnel, I am pretty newish to networking  but want to know if this is normal behavior for a IPsec connection Site A – Data center has 100/100mb in and out Site B – Home, has virgin media fibre broadband 150mb line gives me around 10mb upload max. I have setup a PfSese server 2.2.6 at data center, my home network has a Draytek 2860. I have a windows 2012 server in DC and when copying a file using windows explorer from home using a windows 7 machine I get speeds of around 1.5MB when copying the file to DC I have also tried using PfSese at home to see if the draytek router was the issue, made no difference in speeds. I have also tested IPsec using draytek router to draytek router noticed very poor speeds when copying a files across using explorer. I have tested copying files across using FTP getting similar speed to windows explorer I have used iperf to test speeds beteen A-site and B-site and showing up as decent bandwidth. Perhaps I am not understanding something or some kind windows SMB limit etc ? CLIENT Connecting to host 172.16.1.10, port 5201 [  4] local 192.168.50.102 port 50364 connected to 172.16.1.10 port 5201 [ ID] Interval          Transfer    Bandwidth [  4]  0.00-1.00  sec  1.38 MBytes  11.5 Mbits/sec [  4]  1.00-2.00  sec  1.25 MBytes  10.5 Mbits/sec [  4]  2.00-3.00  sec  1.38 MBytes  11.5 Mbits/sec [  4]  3.00-4.00  sec  1.12 MBytes  9.44 Mbits/sec [  4]  4.00-5.00  sec  1.00 MBytes  8.38 Mbits/sec [  4]  5.00-6.00  sec  1.00 MBytes  8.39 Mbits/sec [  4]  6.00-7.00  sec  1.00 MBytes  8.39 Mbits/sec [  4]  7.00-8.00  sec  640 KBytes  5.24 Mbits/sec [  4]  8.00-9.00  sec  1.00 MBytes  8.38 Mbits/sec [  4]  9.00-10.00  sec  896 KBytes  7.34 Mbits/sec [ ID] Interval          Transfer    Bandwidth [  4]  0.00-10.00  sec  10.6 MBytes  8.91 Mbits/sec                  sender [  4]  0.00-10.00  sec  10.5 MBytes  8.81 Mbits/sec                  receiver iperf Done. SERVER SIDE Server listening on 5201 –--------------------------------------------------------- Accepted connection from 192.168.50.102, port 50363 [  5] local 172.16.1.10 port 5201 connected to 192.168.50.102 port 50364 [ ID] Interval          Transfer    Bandwidth [  5]  0.00-1.00  sec  1.16 MBytes  9.71 Mbits/sec [  5]  1.00-2.00  sec  1.38 MBytes  11.6 Mbits/sec [  5]  2.00-3.00  sec  1.33 MBytes  11.1 Mbits/sec [  5]  3.00-4.00  sec  1.13 MBytes  9.44 Mbits/sec [  5]  4.00-5.00  sec  1.09 MBytes  9.13 Mbits/sec [  5]  5.00-6.00  sec  954 KBytes  7.81 Mbits/sec [  5]  6.00-7.00  sec  986 KBytes  8.07 Mbits/sec [  5]  7.00-8.00  sec  653 KBytes  5.36 Mbits/sec [  5]  8.00-9.00  sec  1020 KBytes  8.35 Mbits/sec [  5]  9.00-10.00  sec  795 KBytes  6.51 Mbits/sec [  5]  10.00-10.10  sec  130 KBytes  10.9 Mbits/sec [ ID] Interval          Transfer    Bandwidth [  5]  0.00-10.10  sec  0.00 Bytes  0.00 bits/sec                  sender [  5]  0.00-10.10  sec  10.5 MBytes  8.73 Mbits/sec                  receiver –--------------------------------------------------------- Server listening on 5201 Actually i think I'm getting confused here, the file transfer i get using explorer is roughtly 1.5MB/s 1 MB/sec = 8Mbps, so 1.5MB/s x 8 = 12Mbps, which kind of means there is no problem i just lacked basics foundations binary a network guys explained this to me which kind does add up.
  • One way IPSEC VPN 2.2.6

    3
    0 Votes
    3 Posts
    1k Views
    I
    Hi, thanks for the response. I do though. On both sides, I have the following: ID Proto Source Port Destination Port Gateway Queue Schedule Description IPv4 * 172.16.10.0/24 * 172.16.20.0/24 * * none IPv4 * 172.16.20.0/24 * 172.16.10.0/24 * * none Is it indicative of something that on the working side, the rule matched does not appear to be one of these I manually added? ih
  • AWS/VPC Ipsec + BGP - 1 tunnel works, 2 tunnel disconnect every 40sec

    1
    0 Votes
    1 Posts
    711 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.