• Is VPN broken in 2.1

    8
    0 Votes
    8 Posts
    2k Views
    D
    So, like… how about posting the contents of /var/etc/ipsec/racoon.conf file?
  • MOVED: IPSEC NO PERMITE CONEXIONES PARA SUBREDES

    Locked
    1
    0 Votes
    1 Posts
    585 Views
    No one has replied
  • IPsec passthrough not working with Xbox One

    3
    0 Votes
    3 Posts
    3k Views
    P
    I have been having the same problem. When I just connect my Netgear router, all works well.
  • Multiple subnets/identifiers with Mobile IPSEC?

    4
    0 Votes
    4 Posts
    1k Views
    jimpJ
    None of that really applies to Mobile. There isn't a way in IPsec currently to restrict access for a given IP/PSK in the way you're after. If this is for site to site, use individual tunnels, not mobile. If it's for mobile clients, the Phase 2 entries are only really used if you check the box to supply a list of networks to the client, and then only if they obey that list. Mobile setups let the client specify what they want to send, the server can't really restrict that (except with firewall rules)
  • Identical subnets on client side

    3
    0 Votes
    3 Posts
    950 Views
    H
    Thank you dotdash! I didn't cross my mind that I could set the source subnet (our side) to the customer's server (/32) instead of the subnet. And I will have a look at NAT too.
  • IPSEC passthrought transparent pfsense

    3
    0 Votes
    3 Posts
    1k Views
    K
    Hello iamzam, thanks for your reply. I've added the rule to allow AH but it also didn't work.
  • Azure to pfSense IPSec Tunnel - DNS issues

    4
    0 Votes
    4 Posts
    1k Views
    N
    …and with that response, I honestly figured it out.  Sheesh!  Why didn't I remember to allow UDP across my tunnel?  DNS works fine now.  Thanks!
  • Route traffic between multi IPsec tunnel with NAT

    1
    0 Votes
    1 Posts
    899 Views
    No one has replied
  • LDAP xauth + IPSec

    21
    0 Votes
    21 Posts
    15k Views
    C
    Follow up: When debugging and redacting previous post I've disabled a second IPSec tunnel (one for point-to-point VPN, not mobile clients) and now mobile client access seems to work just fine (using Shrew Soft VPN Connect software and builtin iOS client). ("Unknown Gateway/Dynamic" log message is still there though) I'll look into the settings of this second tunnel later (time to confirm that at least everything is OK with one tunnel).
  • Need ability to support 50mbit throughput with VPN

    4
    0 Votes
    4 Posts
    1k Views
    J
    @kapara: Been doing some research on AESNI and it looks like even using a corei5 proc can provide significant improvement.  Anyone test AESNI on pfsense yet? Yes, don't bother.  AES-NI makes no difference at this point, though I wouldn't buy a CPU without it as better support is in the pipeline.
  • Slow IPSec VPN pfSense to pfSense

    1
    0 Votes
    1 Posts
    960 Views
    No one has replied
  • IPSec authentication using Active directory

    3
    0 Votes
    3 Posts
    1k Views
    P
    I would suggest checking that you have correctly specified the Search Scope and Base Containers properly. PM me if you still have troubles - I have the Microsoft AD part of IPSec working, but now I'm getting asymmetric routing I suspect. :(
  • Best VPN option for AD/RRAS?

    3
    0 Votes
    3 Posts
    1k Views
    C
    Aye, that may be. We've got a heavily virtual environment so for us its zero marginal cost to spin up another VM for that purpose. Though I am intrigued by OpenVPN. That it can export a setup executable is really cool. I might just go with that instead. Other thoughts?
  • Ipsec passive on

    4
    0 Votes
    4 Posts
    1k Views
    V
    chflags schg filename If you want to be sure that command changed attributes correctly: ls -lo filename -rw-r–r--  1 root  wheel  schg 193 Aug  1 09:20 filename After, if you need to change it again, it will be sufficient to remove protection attributes with: chflags noschg filename
  • IPsec Tunnel initiates on wrong interface.?

    2
    0 Votes
    2 Posts
    752 Views
    jimpJ
    Do both of your WAN interfaces have the same gateway, perhaps?
  • On and Off again VPN using IPSec

    3
    0 Votes
    3 Posts
    1k Views
    O
    I am having the same problem with this, it will not re-establish from CISCO side, no problem from pfsense to CISCO site
  • IPSEC VPN not connecting automatically from main site

    1
    0 Votes
    1 Posts
    735 Views
    No one has replied
  • New VPN - no traffic

    5
    0 Votes
    5 Posts
    1k Views
    ?
    I lately had repeated problems with IPsec tunnel (well doing over months), that after the provider did some "service" the tunnel was not functional (no ping, no data passing) for some hours, although the tunnel was successfully established according to racoon protocolls on BOTH sides. Strange, strange, maybe NSA had no capacity to handle more man-in-the-middle? :)
  • PfSense IPSEC and H.323 Avaya IP phones not routing

    4
    0 Votes
    4 Posts
    1k Views
    D
    I've put accept on all interfaces and log, but no logging of drooped or accepted udp packets. At closer look to the UDP packets I could see that the frame header has the 802.1Q part with VLANID 0. The old router accepted this packets, but not pfsense.
  • Configure an IPSec VPN client?

    2
    0 Votes
    2 Posts
    881 Views
    M
    I'm honestly surprised that they can block OpenVPN. We have ours setup so it tries UDP on a weird port –- If that doesn't work it will revert to TCP port 443 so it is very difficult to distinguish from HTTPS. Even if you can't make a tunnel with SSH, I'm sure you can make an SSH tunnel back to a server that can handle SSH tunnels. Honestly we stopped handling OpenVPN on PFSense due to everyone being disconnected when the firewall fails over.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.