• Entire PF host locks up when changing VTI MTU

    1
    0 Votes
    1 Posts
    275 Views
    No one has replied
  • My battle with Site-to-Site IPSEC (VTI): A tutorial of sorts

    1
    3 Votes
    1 Posts
    1k Views
    No one has replied
  • IPsec Mobile Clients don't receive traffic seen on IPsec interface

    1
    0 Votes
    1 Posts
    232 Views
    No one has replied
  • NAT with multiple Phase2 entries does not seem to work correctly

    3
    0 Votes
    3 Posts
    264 Views
    M
    I am seeing the same thing here. I have the split connections box checked. Remote side has x8 P2's to our side which has x1 NAT'd IP Tunnel will come up with all x8 P2's up and working... after a period of time one or two or three will disappear and will not show in IPSEC status as a child that is down. I also note that the widget in the portal does not display the correct number of tunnels that are up and active. ver 2.4.5 rel + XG1537HA
  • Multiple Phase2 entries does not seem to work in IPSec.

    4
    0 Votes
    4 Posts
    561 Views
    S
    @jimp said in Multiple Phase2 entries does not seem to work in IPSec.: uld try it again but use a unique value corresponding to e 172.31.1.60 and 10.10.10.1 ip for lan interfaces 172.31.1.91<Nat>10.255.68.201
  • One static, 1 dynamic address ...

    2
    0 Votes
    2 Posts
    289 Views
    O
    OK. For anyones interest this does work. 1 - Turn off automatic firewall creation on the pfsense. 2 - Set the wan address in phase 1 to 0.0.0.0 3 - In phase 1 advanced select responder only. 4 - Create any/any firewall rule in IPSEC rules. 5 - Create UDP/500, UDP4500 and ESP all rules. And we have sucess, thanks in no small part to some very patient support staff.
  • ipsec rsa auth issue

    Moved
    5
    0 Votes
    5 Posts
    445 Views
    jimpJ
    No, It's me stating that it works fine for myself and others, and requesting more information (which you still did not provide). If you give us enough information to help, we can help, but so far you have not given us anything to go on. We need details, such as logs and specifics about your configuration (like screenshots).
  • DNS IPSEC

    1
    0 Votes
    1 Posts
    256 Views
    No one has replied
  • OPENVPN and IPSEC on same pfsense SG3100 ?

    3
    0 Votes
    3 Posts
    218 Views
    O
    @Rico thanks, that will mean my problems are elsewhere !
  • DNS not working for Ipsec clients

    2
    0 Votes
    2 Posts
    186 Views
    C
    @cre8toruk Duh.. added UDP any any on the ipsec interface and voila ! Schoolboy error there ! :-)
  • IPSEC pfSense to PaloAlto

    2
    0 Votes
    2 Posts
    436 Views
    M
    just forgotten one thing - the pfSense located on behind router with forwarding UDP ports 500,4500 to it..
  • Encrypted GRE tunnel from Pfsense to Cisco Router

    6
    0 Votes
    6 Posts
    1k Views
    J
    No worries. Thanks anyways!
  • VPN error in logs every few mins, everything works but

    1
    0 Votes
    1 Posts
    215 Views
    No one has replied
  • IKEv2 with EAP-MSCHAPv2 changing from IP to DNS name

    2
    0 Votes
    2 Posts
    303 Views
    jimpJ
    You shouldn't need to touch the cert on the clients. They would only have the CA, not the server cert. All you need to do is change the server cert and then change where the clients connect. And for the record, the cert should have the hostname and IP address in the SAN list. But if you put the hostname in the CN, pfSense automatically adds a SAN for that as well, so it should be fine.
  • Interface (ipsec6000) not being added for VTI tunnel

    6
    0 Votes
    6 Posts
    646 Views
    M
    I changed it to use a gateway group, as per https://forum.netgate.com/topic/52963/ipsec-multi-wan-failover now it works as expected.
  • IPsec tunnel(s) to 1 host with no network behind it.

    1
    0 Votes
    1 Posts
    199 Views
    No one has replied
  • IPsec and OpenVPN

    1
    0 Votes
    1 Posts
    301 Views
    No one has replied
  • Adding a second IPSec Tunnel to a different gateway

    1
    0 Votes
    1 Posts
    190 Views
    No one has replied
  • IPSEC mobile client question - DNS and Routin

    1
    0 Votes
    1 Posts
    251 Views
    No one has replied
  • IPSEC Phase 2 address configuration causing SSL

    ipsec ssl error ssl timeout
    2
    0 Votes
    2 Posts
    493 Views
    C
    More details are in the attached file. I cannot seem to add it here, because it's supposed spam. A little frustrating. MoreDetails.txt
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.