• IPSEC Mobile Beta 4 Broken ?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H

    I have some mobile IPSEC scenarios where clients or other pfSenses and m0n0s join as mobile clients as they have dynamic IPs. I don't see any issues with these. I also have a colleague using SSH-Sentinel to join with his notebook his homenetwork (it even works with a dyndns account at the pfSense at his end).

    Can you get us some logs of both ends (pfSense systemlogs and clientlogs though I don't know this client)?

    Also make sure that your client is behind a device that supports IPSEC Passthrough and there are no restrictions to use IPSEC. IPSEC uses some special protocols that have to be handled correctly.

  • IPSEC/L2TP

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    H

    Yes, it will be present in the upcoming version 1.1 of pfsense, not in 1.0.

  • IPSEC/L2TP

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    S

    Already exists in -HEAD.

  • Ipsec between 2 sites

    Locked
    4
    0 Votes
    4 Posts
    6k Views
    H

    LAN A–-----------------LAN/pfSenseA/IPSEC-----------------------IPSEC/pfSenseB/LAN---------------LAN B

    Don't get confused that it looks like a seperate Interface up there. IPSEC is completely transparent between the two pfSenses once established, it doesn't cross the WAN interfaces even (seen from the packetfilters view).

    As I said you only can control incoming connections on an interface. So the rules at the LAN interface of pfSenseA determines what can move over the IPSEC to pfSenseB. pfSenseB can't block connections incoming over IPSEC as it's not an interface seen by the packet filter. The same applies for the other direction. Rules at LAN interface of pfSenseB can pass/block traffic going through the IPSEC to pfSenseA only.

    I hope this makes it a bit more clear.

  • 1.3 and IPSec Tunnels - Can't Authenticate with Certificates?

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • PF Sense & Ipsecuritas

    Locked
    4
    0 Votes
    4 Posts
    5k Views
    H

    check the ipsec logs of both sides (client and pfsense). You might find a hint there.

  • Anyone knows diferences between IPSEC - OpenVPN?

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    A

    can i create rules in open vpn ?

  • Using ADSL with DynDNS. How configure My identifier?

    Locked
    7
    0 Votes
    7 Posts
    6k Views
    D

    @hoba:

    That's actually not a real error. it just tells you that there already was a policy for this connection but it got replaced when you edited the tunnel. It should simply work. I have the exactly same config using a pfsense with static IP and another pfsense and a m0n0 joininng with dynamic IPs. It's working for more than a month already without any glitches.

    It´s working. Just like the tutorial show. I´ve solved some bugs in my configuration and that´s all.
    Thanks everyone.
    Diego

  • Connect 2 PC using IPSEC tunnel or one may be mobile client??

    Locked
    4
    0 Votes
    4 Posts
    5k Views
    D

    @diegote:

    I´ve tried to connect 2 PC using IPSEC tunnel. This is correct? or one has to be Mobile client?? Somebody could create a tunnel?? I`ve tried so many configurations and nothing (in SAD nothing, in SPD always show 2 records, for incoming and outgoing policy).

    It works!!!! in a private LAN.
    Im trying to connect an ADSL (mobile client) to a Static IP. I´m using the configuration show in the tutorial with the FQDN (email & secret key) but doesn´t work. Ive copied LAN private configuration (for de phases, not the Network config).

    The funny thing is, I could create a tunnel using ADSL IP like static IP, and the real static IP on the other side.

    THANKS A LOT FOR EVERYTHING!!!!

  • How to route traffic over ipsec vpn?

    Locked
    7
    0 Votes
    7 Posts
    19k Views
    H

    I answered that at the m0n0 list a long time ago in a galaxy far far away: http://www.m0n0.ch/wall/list/showmsg.php?id=160/29
    It's the same situation with pfSense atm. Using static routes across VPN-Tunnels doesn't work yet.

  • Traffic Stop on IPSec Connectin

    Locked
    6
    0 Votes
    6 Posts
    5k Views
    S

    Problem ist the default MTU Setting from D-Link DFL-1100.

    after change the MTU from 1424 to 1472 Filetransfer and also intranet websites will work now.

    http://forum.pfsense.org/index.php?topic=927.msg5562#msg5562

    Why MTU 1472 ? I try on a workstation behind pfsense to ping a workstation behind the D-Link.

    ping 172.16.170.8 -f -l 1472

    Ping wird ausgeführt für 172.16.170.8 mit 1472 Bytes Daten:

    Antwort von 172.16.170.8: Bytes=1472 Zeit=47ms TTL=126
    Antwort von 172.16.170.8: Bytes=1472 Zeit=48ms TTL=126

    ping 172.16.180.8 -f -l 1473

    Ping wird ausgeführt für 172.16.180.8 mit 1473 Bytes Daten:

    Paket müsste fragmentiert werden, DF-Flag ist jedoch gesetzt.
    Paket müsste fragmentiert werden, DF-Flag ist jedoch gesetzt.

    Ping-Statistik für 172.16.180.8:
        Pakete: Gesendet = 2, Empfangen = 0, Verloren = 2 (100% Verlust),

  • Error in Log

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    P

    Looks like user error was to blame as I was able to get my IPSec tunnel up with my workplace's NetScreen firewall.

    Thanks,

    – Phob

  • IPsec connection to commercial CISCO VPN?

    Locked
    5
    0 Votes
    5 Posts
    7k Views
    I

    Thanks CMB, it's possible my client is out of date on the machine so I'll upgrade it over the next or two and post my findings back.

  • VPN client Windows XP

    Locked
    3
    0 Votes
    3 Posts
    5k Views
    C

    @kph:

    Does anyone know a working (free?) vpn client for Windows 2000/XP? that can connect to a PFsense (beat2) machine, without having to open any external ports (500 UDP)

    without having to open ports?  No.  I've never heard of any VPN client, commercial or otherwise, that lets you connect without any open ports.  You could combine something like port knocking with a VPN client to accomplish this.

    @kph:

    ps. does anyone know why they Cisco VPN client does'nt work with PFsense (beta2)?

    Because it's not a normal, standard IPsec VPN client.  It requires xauth, which isn't going to be supported in 1.0.

  • PfSense IPSec Connection to D-LINK DFL-1100 ?

    Locked
    8
    0 Votes
    8 Posts
    7k Views
    S

    ok thanks,
    will work now also with static tunnel.
    I have changed my lan IPs so routing is easyer..

  • Multiple IPSec Passthrough?

    Locked
    4
    0 Votes
    4 Posts
    6k Views
    S

    I'm happy to report that two IPSec passthrough connections work just fine from two different hosts into two different servers.

    One is Sonicwall GVPN client to my employer's Sonciwall server.  The other is Contivity client to a customer's server.

    In fact I should be able to test a third simultaneous connection tonight.  It'll also be Contivity, but into a third server.  I have other client software, but don't think I have any other currently active accounts to test with.

    I'm tickled – this was always somewhat problematic with previous firewall/NAT devices.

  • IPSEC Subnets

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    H

    I don't know if I understand you but PPTP has nothing to do with IPSEC. There are fields for specifying the subnetmask for each network when editing the tunnels. Maybe http://pfsense.com/mirror.php?section=tutorials/mobile_ipsec/ will get you started though this handles some kind of "special" configuration.

  • Firewall rules in IPSec tunnel

    Locked
    4
    0 Votes
    4 Posts
    5k Views
    S

    Re-read what hoba said carefully.

  • Maximum number of connections/tunnels

    Locked
    4
    0 Votes
    4 Posts
    5k Views
    S

    are you using wraps running pfsense or anything else?

  • Net to Net with pfsense ?

    Locked
    11
    0 Votes
    11 Posts
    7k Views
    S

    Again, its an issue with the client.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.