• command for ip xfrm state

    3
    0 Votes
    3 Posts
    941 Views
    M
    @konstanti said in command for ip xfrm state: ipsec statusall or swanctl --list-sas or setkey -D Thanks a lot!
  • Ipsec VPN between Fortigate with NAT

    1
    0 Votes
    1 Posts
    323 Views
    No one has replied
  • No reaction in IPSec logs, how to debug? (vodafone station)

    1
    0 Votes
    1 Posts
    330 Views
    No one has replied
  • PHP/Apache REMOTE_ADDR not resolving as expected when connected via IPsec

    2
    0 Votes
    2 Posts
    375 Views
    B
    Just checked: I have the same behavior with OpenVPN?! Maybe I'm stupid, but I don't understand this. Please enlighten me
  • ipsec rules not working

    5
    0 Votes
    5 Posts
    753 Views
    stephenw10S
    Nope in addition to port 21 you need to pass the passive port range, for eaxmple 10000-20000 but that that could be anything depending on how you've configured it. Also vsftp seems to use ftps so needs port 990 also for the encryption. See: https://www.howtoforge.com/tutorial/ubuntu-vsftpd/ You should be able to see that traffic blocked in the firewall log though when you try to connect and it fails. Steve
  • Has anyone got a VPN to a Draytek working?

    Moved
    36
    0 Votes
    36 Posts
    18k Views
    A
    You should not really have an issue with a Draytek to ASA VPN, we have many of those running on multiple ASA firmwares and 2820s, 2860s (v3.9.4.1), 2862s, 29xx etc. I can't specifically tell you how, as I am not the Cisco guy :-) If it helps most of ours run on IKEv1 with 3DES with auth, no PFS. We also run all the tunnels outbound on the Draytek to the Cisco., with P1 28800 and P2 3600, which is the Draytek default. The solution is reasonably well documented on the Draytek knowledge bases and forums, and your Draytek reseller should have access to Draytek tech support, who are pretty helpful most of the time if you are clear on what the problem is. Not wishing to undermine stephenw10 on the pfSense sell ;-), we have had no luck really in getting Draytek to play with pfSense running in Azure. Despite our best efforts we cannot get a stable solution. We can get pfSense to work with ASA all day long though, so it depends which end you might switch out for a pfSense.
  • States getting killed after every renegotiation with Sonicwall

    1
    0 Votes
    1 Posts
    187 Views
    No one has replied
  • 0 Votes
    2 Posts
    351 Views
    M
    Hi all , i should put that at the top of the topic, sorry.
  • 0 Votes
    2 Posts
    1k Views
    S
    Great idea! mac OS Big Sur & iOS 14.3 Phase 1: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_2048 IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/ECP_256 IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1536 IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024 IKE:3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024 Phase 2: ESP:AES_CBC_256/HMAC_SHA2_256_128/NO_EXT_SEQ ESP:AES_CBC_256/HMAC_SHA2_256_128/NO_EXT_SEQ ESP:AES_CBC_256/HMAC_SHA2_256_128/NO_EXT_SEQ ESP:AES_CBC_128/HMAC_SHA1_96/NO_EXT_SEQ ESP:3DES_CBC/HMAC_SHA1_96/NO_EXT_SEQ
  • Problem with IPSEC between Pfsense 2.4.5 and Cisco ASA

    1
    0 Votes
    1 Posts
    267 Views
    No one has replied
  • IPsec stability and frequent CHILD_SA CREATE / DELETE

    2
    0 Votes
    2 Posts
    474 Views
    V
    pfSense version is: 2.4.5-RELEASE-p1 (amd64)
  • Dropped ipsec / fragmented UDP packets

    7
    1 Votes
    7 Posts
    1k Views
    C
    @derelict Someone is, however :)
  • IPSEC IKEV2 MS CHAP V2

    3
    0 Votes
    3 Posts
    621 Views
    B
    @jimp Right now I’m using a LastPass generated password 16 charachter and just saving the credentials . Just abit concerned about this approach as it’s just 1fa , I’m saving the password and the vpn gives full access to my network Also, what does using certificates protect against ? Not sure on how it enhances security
  • IPSEC NOT WORKING

    1
    0 Votes
    1 Posts
    336 Views
    No one has replied
  • Help needed with IPSec Tunnel

    1
    0 Votes
    1 Posts
    149 Views
    No one has replied
  • Route to IPSec Tunnel from OpenVPN Client

    4
    0 Votes
    4 Posts
    626 Views
    bingo600B
    @sgnoc Cool Great that my brainstorming was of help /Bingo
  • IPSec VPN not really working

    Moved
    3
    0 Votes
    3 Posts
    478 Views
    B
    After even more investigation: Seams like the rules from WAN to pfSense where in place and effective. But what was missing: An allow rule from IPSec to the LAN. Is this "works as designed"? Even the DNS (the pfSense itself) was not reachable...
  • IPSec with a certificate provided in ACME

    1
    0 Votes
    1 Posts
    339 Views
    No one has replied
  • IPSec work with no inbound rule in firewall

    5
    0 Votes
    5 Posts
    573 Views
    F
    Everything is explained. Thank you for your answers!
  • IPSEC IKEV2 2fa

    1
    0 Votes
    1 Posts
    246 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.