• 2.2.2 -> 2.2.3 Upgrade: KeyID Tag Broken?!

    4
    0 Votes
    4 Posts
    1k Views
    C
    This was fixed in 2.2.4 last week.
  • [2.2.3] High CPU usage when going to the IPSec status page - Lot of SAD

    1
    0 Votes
    1 Posts
    829 Views
    No one has replied
  • Route a WAN IP over the tunnel

    5
    0 Votes
    5 Posts
    1k Views
    M
    After disabling and enabling the phase 2 on one end, the tunnel came up. It was not possible to ping through the tunnel but it looks like the routing works. I then checked the ipsec firewall roules but they were ok (IPv4 * * * * * * none). I also added such rules on the lan interface on both ends. Still, the ip is not pingable. EDIT: After adding an outbound NAT rule and switching to hybrid mode, I can finally reach through the tunnel. Adding a third phase 2 shows the red arrow again on this phase 2. Re-enabling it does not help, even after a few times. The ipsec log shows the phase 2 as if it was connected: charon: 10[CFG] received stroke: add connection 'con1002' Jul 7 22:29:48 charon: 10[CFG] added child to existing configuration 'con1000' Jul 7 22:29:48 charon: 07[CFG] received stroke: route 'con1002' Jul 7 22:29:48 ipsec_starter[35735]: 'con1002' routed But the red arrow on the status page stays and the tunnel is not connected in fact.
  • IPSec Tunnel IKE2 to ASA does only the last SA; not all 4

    9
    0 Votes
    9 Posts
    3k Views
    A
    Still waiting for help; yes, it works fine under IKEv1; but need to have it working in IKEv2.  ;) Either with hack, or NATting 4 (was 2 before) local subnets 10.1.10.10/24,10.1.10.20/24,10.1.10.110.110/24, and 10.1.10.120 into 10.41.38.0/22, so we can only use 1 SA. Tried NAT 1:1 but that did not work. Any help appreciated.
  • IPsec between pfsense and ZyWall usg100-plus with certificates

    1
    0 Votes
    1 Posts
    646 Views
    No one has replied
  • Creating a rule for IPSEC VPN

    1
    0 Votes
    1 Posts
    654 Views
    No one has replied
  • New IPSEC Tunnel ISAKMP Rule Not Being Auto Created

    1
    0 Votes
    1 Posts
    810 Views
    No one has replied
  • Charon does not match sent identity to configured one

    5
    0 Votes
    5 Posts
    2k Views
    G
    @cmb: I'm going through all the possible combinations there now doing testing, with an automated test setup to iterate through all the possibilities. We'll have that resolved for 2.2.4. Awesome!  :D
  • Ipsec to asa 5545x drops every few minutes

    2
    0 Votes
    2 Posts
    613 Views
    R
    Can you post debugging logs of both sides?
  • Ipsec vpn using x.509

    2
    0 Votes
    2 Posts
    729 Views
    Z
    i have tried specifing the wan ip address as CN in the certificate …. no luck. can anyone share their experience on ipsec with rsa please?
  • FrotiClient VPN

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • IPSEC VPN borked

    2
    0 Votes
    2 Posts
    3k Views
    C
    Double check your configuration. IKEv1, main mode? If you had something that worked, it came up, then you changed something so it no longer matches (like switching to IKEv2 for instance for that log), the already-negotiated connection would stay up for the lifetime. Then come time to rekey, it fails as the config is no longer valid.
  • IPSEC and L2TP issues for a noob>>>

    1
    0 Votes
    1 Posts
    643 Views
    No one has replied
  • Ipsec can't login on pfsense 2.2.3

    1
    0 Votes
    1 Posts
    613 Views
    No one has replied
  • 0 Votes
    3 Posts
    864 Views
    S
    Hi cmb, thanks i have to restart the system and then wait for the error. thank you Thomas
  • VPN from Cisco with redundant wan to pfSense

    2
    0 Votes
    2 Posts
    749 Views
    C
    You can check the "responder only" on phase 1 to accomplish that part of it.
  • Mobile VPN Users accessing Secondary Site over existing IPSEC Tunnel

    1
    0 Votes
    1 Posts
    572 Views
    No one has replied
  • L2TP Problem with CISCO

    2
    0 Votes
    2 Posts
    1k Views
    E
    Anyone? I'm still trying to get this things working…. Thank you!
  • VPN ipsec with one end using dynamic ip changing every 12hours

    9
    0 Votes
    9 Posts
    3k Views
    Z
    hi sorry for the delay, the pfense will be deployed under ESX on a DualXeonE5-2630V3 64GB RAM, the server will also contain 2 vm's for media delivery and proxy. I was thinking on only one concentrator,  didnt know of the existence of hardware crypto accelerators. 100mbps of throughput is required over vpn. will this hardware suffice? Server specs: https://secure.iweb.com/en/classicServerFlex/classicServerFlex/?id=38d2233b4574e196403bbacfcf533339 The peers are cisco using vpn ipsec lan-to-lan with x.509 certificates. edit: read about AES-NI, will this boost even if using 3des/sha?
  • IPsec Mobile Can Only ping router on lan

    2
    0 Votes
    2 Posts
    575 Views
    C
    Is that system the default gateway on your LAN? Can you get out to the Internet via that VPN, just not to your LAN?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.