• Load balancing IPSec over multiple WANs

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Tunnel between two dynamic sites

    Locked
    12
    0 Votes
    12 Posts
    8k Views
    X

    Heres my working config:

    local subnet is the local subnet on the fw your on
    remote is the subnet you want to access at the other end
    for remote gateway put in a ddns
    identifier is my ip address, leave blank
    do a pre-shared key, must be the same on both fw's
    keep alive-set this to the fw at the other end
    all other options: set them the same at both ends

  • Connecting Pfsense IPsec behind linksys wireless N router

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    F

    I assume what you are asking is if you can set it up behind the Linksys router and the Linksys router is being NATed. I have done this previously but the device was a Linksys router with VPN capabilities behind a DSL modem that was NATting the traffic. It worked but not reliably. I have used the same Linksys vpn router when not behind a NAT and it does work reliably.

    If you can manage the network I would suggest using your pfSense box for the main router and then turn off the routing capabilities of the Linksys router and just let it continue to be an access point.

  • Send syslog data trough tunnel, possible?

    Locked
    2
  • VPN IPSEC between PFSense and Cisco ASA 5505

    Locked
    6
    0 Votes
    6 Posts
    21k Views
    jimpJ

    Try using a different encryption method such as AES-128 which would be faster than 3DES.

    Are you also monitoring the CPU and such on the ASA? I wouldn't think that little of traffic would tax it though.

    It may also be the protocol you are using. Some things might be fast, such as http downloads, while others would be slow (SMBv1 windows shares).

  • Site to site ipsec

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    F

    There are two actual possible places to disable the ipsec service from starting  and I am sure there is a reason for this.

    The general one disables IPsec completely for all tunnels. The disable checkbox that you had checked in the config for the actual tunnels is to disable one tunnel while leaving others enabled.

  • IPsec fail on ADSL PPPoE reconnect

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    Use 1.2.3 everywhere. Many of those issues have been solved over time.

  • Route Trafic to 2nd remote Subnet Through IPSEC!!! S.O.S

    Locked
    3
    0 Votes
    3 Posts
    5k Views
    M

    It worked. I made the second IPsec Tunnel added some rules and works grate!

    Thank a lot.

  • One way traffic

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    J

    Does anyone have any ideas how to stop this multiple tunnel issue.

  • IPsec Config Netopia and pfsense

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    W

    I change the IP's in the config before posting it, thanks for the tip though.

  • IPSec troubles (solved)

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    E

    Solved my problem

    PFsense 1 still had his second connection cached (now used for pfsense2) There for expected the wrong ip

    Also ran into not being able to ping but that was simple adding ICMP rule. Hope this might help some one else out

  • IPSEC between 2 offices

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    E

    Well we need more info then: It doesn't work did you read this ?

    http://doc.pfsense.org/index.php/VPN_Capability_IPsec

  • Ipsec dies after a while

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    E

    when checking into my own problems i saw this remembered it

    http://doc.pfsense.org/index.php/IPsec_Troubleshooting

    ERROR: pfkey DELETE received

    You might see this message repeatedly as Phase 2 is renegotiated between two endpoints (for multiple subnets). The tunnels still work, but traffic may be delayed while the tunnel is switched/reestablished. (more research needed for possible solutions)

  • Site to Site between Netscreen 5GT and PfSense

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    jimpJ

    Try some of the suggestions here:

    http://doc.pfsense.org/index.php/IPsec_Troubleshooting

    And also you might double check the firewall rules on the pfSense side, and the Netscreen side if it is capable of filtering IPsec traffic.

  • Ipsec roadwarrior

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    C

    It works from behind the pfsense box also now, esp protocol was still blocked.

    thanks for the help and have a nice weekend !!!

  • Free ipsec software client

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    C

    I will check it out ..

    thanks

  • Compression_algorithm deflate

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • 0 Votes
    5 Posts
    3k Views
    C

    @saxd40:

    It appears that this issue still exists in 1.2.3-RELEASE.  I never had issues with IPsec tunnels in old versions of pfSense, but ever since I upgraded to 1.2-3-RELEASE 6 months or so ago I've been having intermittent issues with tunnels hanging.  In the last few days this has started being 3-5 outages per day (or more).

    Are you using carp on the master site (two firewalls) ?

    I'have a lot of ipsec tunnels, towards pfsense boxes and cisco routers (837,857 and 877).
    I am using 'Prefer old IPsec SAs', and when A remote routers reboot (like AC loss) I must reboot the Firewall Master Node.
    When 'Prefer old IPsec SAs' is off, the tunnel goes down after the phase1 lifetime.
    From Ipsec status I always see green icons.

    PS:I suggest to use openvpn (when you have firewalls on both sides :P )

    Giacomo

  • /var/etc/racoon.conf missing

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    jimpJ

    Using the physical NIC directly and a VLAN on the same NIC is rarely a good idea.

    Are you sure what you are trying to do with WAN/vlan1 actually makes sense?

  • IPSec - My Identifier in Phase 1 Proposal

    Locked
    4
    0 Votes
    4 Posts
    6k Views
    jimpJ

    Yes, it means WAN IP Address.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.