• Site to site

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    S

    Okay now the sites are working.  ???
    Now I`m going to try and add a
    adtran netvanta 2300,and a
    cisco 2600 into the mix.
    Looks like the adtran will not support blowfish encryption.

  • IPSec on OPT1

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    T

    @hoba:

    The static routes are still needed. Autocreation of this is a bit tricky currently. Maybe we'll implement this later (after 1.2 is out).

    Where do the static routes point to?

    other question: does it work with one PFsense box on the WAN IPSEC port/tunnel and one PFsense box on the OPT IPSEC port/tunnel?

  • Multiple wan, multiple mobile clients

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Is this pobible?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    U

    I answer myself. Is posible. The problem was the two diferents versions of pfsense.

    Cheers

  • IPSEC with especific Lan address but in diferent network of Lan

    Locked
    10
    0 Votes
    10 Posts
    4k Views
    J

    Hi, now I cam stablish a VPN with a Vlan on WAN interface but i cam only ping fron the pfsense itself.

    Any sugestion on how i cam make a route, nat or a rule from the LAN 192.168.0.0/24 to a VLAN 78.0.10.96/28.

  • IPSec with pfSense 1.2-BETA-1 on Soekris 4801 crash & reboot problem

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    R

    I've got some WRAP boards that are very similar to the Soekris 4801. 128MB RAM and 266 MHz. I had a problem with 3DES VPN rebooting them if I sustained VPN traffic for more that about 10 seconds if the other side was capable of handling more than about 4 mb/s. With a VPN1411 card in each, I sustained almost 9 mb/s with no reboots between 2 of them. This was not with the new beta version though. I haven't run it on an embedded platform yet. Here's the thread on my throughput testing.

    http://forum.pfsense.org/index.php/topic,1869.0.html

  • Filter reload error - "USER_RULE: Permit IPSEC traffic…"

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C

    What's the exact version you're running? Can you replicate it with the latest snapshot from
    http://snapshots.pfsense.org/FreeBSD6/RELENG_1_2/

  • 0 Votes
    7 Posts
    6k Views
    S

    I tested it with pfSense-Full-And-Embedded-Update-1.2-BETA-1-TESTING-SNAPSHOT-06-06-2007.tgz today. But the parallel tunnel is not available with the latest update too.

    Pls Pls fix this problem. I think parallel tunnel is a very usful ipsec function.

    Thank you.

  • WAN <> OPT3 TUNNEL PROBLEMS

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Tunnel troubles

    Locked
    19
    0 Votes
    19 Posts
    9k Views
    C

    @covex:

    well… i have about 40 linksys befvp41 and 10 netgear fvs318v3 connected to pfsense box. besides minor missconfiguration problems everything work fine.

    Wow, so they're actually stable? I cringe at the thought of supporting 40 Linksys VPN boxes.  ;D  I've tried the BEFVP41, granted it was probably 5 years ago, but at the time it didn't work reliably at all no matter what I connected it to.

    I think I still have it on a shelf around here somewhere, maybe it's time to give it another shot if for nothing other than the sake of documenting the proper way to configure one to connect to pfsense.

  • IPSec problem

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C

    after 24 hours this message went away by itself  :-
    i hate when things fix by themselves

  • IPSec not working after Update to 1.2-BETA-1-TESTING-SNAPSHOT-06-04-2007

    Locked
    9
    0 Votes
    9 Posts
    4k Views
    M

    Thanks for that. I have to say I agree that hidden rules are bad. Maybe you could do the same as with NAT and auto create a rule if the check box is checked.

    Either way it needs to be consistent between creating a rule for a carp and a wan. Especially given that the carp address/interface is now selected from the same dropdown as the WAN interface

    Thanks for a great firewall

  • How many simultaneous L2TP connections can pfSense handle?

    Locked
    4
    0 Votes
    4 Posts
    8k Views
    C

    I'm not a Linux guru, and never heard of strongswan until you mentioned it. From a quick Google, it's IPsec for remote access.

    The issue with IPsec is, unless you have a commercial solution that comes with a client (Cisco, probably others), there are issues getting client software on Windows machines (and I assume that's the majority of what you'll need to support). There is the Shrew Soft client, and I know the author hangs out on our mailing list and people do use it with pfsense. http://www.shrew.net/

    OpenVPN is more convenient, IMO, because you can use a single client across every platform you need to support (Windows, OS X, BSD, Linux). With IPsec, you would have a different client from a different source for every platform (again, unless you had a commercial solution).

    If I was going with a large scale open source deployment, I would go with OpenVPN in most environments.

    For around 100 simultaneous connections, I would go with a Pentium 4 or better box. That should leave you plenty of power to spare.

  • Range in SPD.CONF

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • IPSEC does not work with more than one Tunnel

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    S

    Fixed recently:

    http://cvs.pfsense.com/cgi-bin/cvsweb.cgi/pfSense/etc/inc/vpn.inc?rev=1.89.2.29.2.8;content-type=text%2Fplain

  • Routing IPSEC

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Pfsense and isakmpd

    Locked
    9
    0 Votes
    9 Posts
    6k Views
    C

    There were some issues with IPsec and snapshots up until earlier today. Try a new snapshot.

  • MANUAL KEY Ipsec without IKE

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Hi again

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Ipsec VPN from any IP

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.