• multiple connection l2TP behind a NAT

    1
    0 Votes
    1 Posts
    182 Views
    No one has replied
  • IPsec Site-to-Site with NAT

    28
    0 Votes
    28 Posts
    3k Views
    J
    Well, doesn't matter now, I got it properly working using OpenVPN, took all of an hour including coffee time, vs IPsec which has been weeks in the making. Thank you for steering me into the light @Derelict
  • IPSec tunnels going down sometimes when phase 2 renegotiation happens.

    Moved
    2
    0 Votes
    2 Posts
    392 Views
    stephenw10S
    Well you should have everything at p3 anyway. I'm not aware of any particular issue between p2 and p3 though. Do you have any logs showing the negotiation failure from either end? Steve
  • ipsec mobile with 2f Google Authenticator

    2
    0 Votes
    2 Posts
    202 Views
    jimpJ
    You might get that to work with an IKEv1 Xauth style setup. It definitely will not work with IKEv2 EAP, though because EAP won't work with PAP.
  • IPsec advanced settings MSS clamping vs IPsec interface MSS clamping

    5
    0 Votes
    5 Posts
    4k Views
    G
    @Konstanti Thank you! That clears it up! I will be using the settings on the IPsec interface tab.
  • 0 Votes
    1 Posts
    297 Views
    No one has replied
  • VPN IPsec tunnel keeps disconnecting

    1
    0 Votes
    1 Posts
    254 Views
    No one has replied
  • Abandoned SAs associated to an IPSEC tunnel

    2
    0 Votes
    2 Posts
    296 Views
    jimpJ
    It's normal to see extra copies in there depending on how the negotiation/rekey happened. As long as your traffic is flowing and the tunnel rekeys when needed and keeps going, it's not worth worrying about.
  • IPSec Fortigate to pfSense Routing issue

    2
    0 Votes
    2 Posts
    498 Views
    S
    Solved, cause was a false configured policy at the Fortigate. In the policies for (incoming/outgoing) traffic the "NAT" switch was enabled. Why the fortigate choose the ip-adress of the DMZ interface instead the ip of the WAN interface is a mystery to me. So i was wrong when i said i don't have a Network with the IP 192.168.31.9. This IP was configured for an older test scenario but not used anymore and even the interface was not connected.
  • IPSec Site to Site with peer behind CGNAT

    ipsec site-to-site cgnat
    3
    0 Votes
    3 Posts
    4k Views
    M
    For anyone who is interested (n00b here), i got it to work (branch to pfsense only): Phase 1 remote subnet on pfsense has to be 0.0.0.0 with responder only option checked. on Huawei Side, the following command had to be configured: ipsec authentication sha2 compatible enable the result is: [image: 1565666662782-22accdc1-de10-456f-beb1-06c813df2382-image.png] The problem now is that pfsense does not direct traffic with destination to remote subnet (i.e. 10.2.20.0) through IPSec, it uses WAN0 for that. any ideas? [update] working now, was pinging from the wrong device.
  • Better way to connect multiple site to sites than a lot of Phase 2s?

    4
    0 Votes
    4 Posts
    441 Views
    DerelictD
    You might also consider establishing a couple of hubs so you have redundancy and connect all other sites to both of those. A full mesh really does not scale well.
  • IPSEC Site To Site

    9
    0 Votes
    9 Posts
    1k Views
    DerelictD
    Each side should initiate when there is traffic matching the traffic selector. In many cases you can make this happen by setting an automatically ping host to something on the other side in each P2. (it just has to match the remote network - it doesn't actually have to respond to ping). Tunnels generally come up very quickly and the fact that the tunnel was not actually up when the traffic is initiated is not noticed by users or applications.
  • Solved: Can't assign ipsec* Interface

    9
    0 Votes
    9 Posts
    2k Views
    T
    @Derelict doh Thanks a lot ... that was it ;) Thanks
  • Watchguard to Netgate SG-3100

    2
    0 Votes
    2 Posts
    432 Views
    DerelictD
    Probably firewalls (think windows firewall) local on the hosts you are trying to ping. Or Anti-virus, endpoint protection, or some other software on the target host itself.
  • IPsec/L2TP how to see attached clients

    5
    0 Votes
    5 Posts
    3k Views
    C
    @chonkat Status >>> System Logs >>> VPN >>> L2TP Logins Is that what you are looking for?
  • Setting up IPsec VPN pfsense to dsr dlink-1000 router

    32
    0 Votes
    32 Posts
    3k Views
    DerelictD
    And probably about time to ask on the D-Link forums instead of here.
  • Schedules for IPSec tunnels

    8
    0 Votes
    8 Posts
    753 Views
    DerelictD
    @sepp_huber said in Schedules for IPSec tunnels: There is no feature to disable it, it must be deleted to stop billing ... and if you create it again you get a new configuration, not very cost efficient... That's why many people put pfSense in AWS and IPsec to that.
  • [Feature/Extension] Road warrior subnet per EAP-identity

    13
    0 Votes
    13 Posts
    3k Views
    A
    In case the change is not working, do we need to add an another change or bug request somewhere? Because the idea and feature is quite useful.
  • IKEv2 Connects but internet is very slow

    21
    0 Votes
    21 Posts
    2k Views
    DerelictD
    The looks like the ethernet LAN on the client.
  • Site to Site with two pfsense boxes

    9
    0 Votes
    9 Posts
    867 Views
    DerelictD
    You can ping from the pfSense GUI if one of the firewall interfaces is an interesting source for the traffic selector. For instance, if the pfSense LAN network is a local network in IPsec you just need to select LAN as the Source address in Diagnostics > Ping. It sets the -S flag to the ping command.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.