• VPN S2S - Bytes-Out: 0 (0 B) Packets-Out: 0

    ipsec vpn s2s
    2
    1
    0 Votes
    2 Posts
    546 Views
    E
    can you share P2 subnet/IPs of both end, and firewall rule configured on IPSec interface - both ends,
  • No IKEv2 Phase 1 with IPv6 Client

    2
    0 Votes
    2 Posts
    343 Views
    R
    @rsdu Even though the documentation states that firewall rules are added automatically, firewall log shows that incoming traffic is blocked by the "default IPv6 incoming block" rule. I added UDP Port 500 and ESP to the ruleset and there we go ...
  • IPSec wont route traffic, only after 2/3 disconects

    2
    0 Votes
    2 Posts
    283 Views
    M
    @Mr_JinX system logs............ ipsec logs........... Unless you didn't provide the logs on purpose its impossible to say why anything happens anywhere.
  • create an IPSEC route-based connection with one tunnel and two peers?

    1
    1
    0 Votes
    1 Posts
    187 Views
    No one has replied
  • IPSec with custom port

    2
    8
    0 Votes
    2 Posts
    306 Views
    G
    After taking the screenshot, and recognizing the mismatch between the ports, I've updated the PHASE1 settings on both ends, specifying just the NAT-T port. [image: 1721305805900-0dbb0d4a-70c8-496a-87dd-bee9fa740865-image.png] Now, the ports looks coherent. SITE A [image: 1721305847630-5387557b-d330-43ec-a494-e44119f1e484-image.png] SITE B [image: 1721305874011-a0791832-6b78-4a3a-a053-f749822d43b5-image.png] Now ping works :) [image: 1721305914479-996ddfcd-d96a-4b60-9bb5-f194f3ed1fa9-image.png] [image: 1721305938523-08a81d89-236c-44e0-8ecc-26dc19d27d4e-image.png] Still open the question on why this port mismatch happened.....I've lost like 40 hours on this
  • IPsec: The same LAN + VLAN network

    5
    0 Votes
    5 Posts
    445 Views
    P
    @viragomann Thanks for helping me. Your tip worked for me.
  • Phantom ISRG Root X1 CA cert

    1
    2
    0 Votes
    1 Posts
    429 Views
    No one has replied
  • Windows 11 IPSec ESP no acceptable proposal found

    7
    0 Votes
    7 Posts
    2k Views
    keyserK
    @lifeboy When editing the Phase one and Phase 2 settings, only one encryption settings is enabled in both: AES256 and using SHA256 with DH14: [image: 1721142730850-72a1546e-02d3-4f89-bebe-3fc688c05aec-image-resized.png] [image: 1721142765204-937960d9-5daa-465f-a6f4-630ecdc079ac-image-resized.png]
  • all VPN IPSEC connections are down suddenly

    4
    0 Votes
    4 Posts
    441 Views
    P
    @viragomann Hello @viragomann Please see details logs on attachment filelog-ipsec-details-pfsense.txt Thank you for your help Regards
  • Phase 2 drops

    1
    0 Votes
    1 Posts
    170 Views
    No one has replied
  • 0 Votes
    2 Posts
    279 Views
    J
    turns out, it was me. i mistakenly upgraded the secondary node to 2.7.2, but forgot to upgrade the primary node and it was still 2.7.0. HAsync was not working due to this error, so this was not a pfsense problem, it was a me problem :)
  • 0 Votes
    3 Posts
    638 Views
    L
    @michmoor i've founf the problem. When my p1 have multiple p2. It always getting disconnected. I dont know why its happening on latest pfsense version.
  • IPSec behind NAT

    11
    1
    0 Votes
    11 Posts
    1k Views
    X
    @viragomann Before routing the traffic of Server, I would like PFSense01 and PFSense02 to ping on the VTI interfaces, because from the screenshot that I showed before on PFSense01 there are 0 outbound packets, and I don't now why
  • IPSec widget: misleading status, maybe

    1
    2
    0 Votes
    1 Posts
    181 Views
    No one has replied
  • Issues: PFSense VTI X SonicWall

    1
    5
    0 Votes
    1 Posts
    158 Views
    No one has replied
  • 0 Votes
    3 Posts
    333 Views
    T
    Forgot to mention Site A uses Cox Cable and Site B uses Comcast.
  • Editing ipsec.conf

    1
    0 Votes
    1 Posts
    159 Views
    No one has replied
  • IPSec Hub and Spoke Topology

    2
    0 Votes
    2 Posts
    1k Views
    O
    On the Fortinet router make sure you have the necessary firewall policies and the source/destinations for each policy are set up correctly. Please also reference my post on this thread: https://forum.netgate.com/post/1169622 The correct way to set up hub/spoke topology in multi-platform setting would be use 0.0.0.0/0 routing via IPSEC interfraces. However, this was broken in 24.03 and I'm afraid it will be broken in 2.8.0 CE as well, despite this functionality being there for years and working flawlessly.
  • Ipsec behind NAT to Public IP

    5
    0 Votes
    5 Posts
    808 Views
    P
    @viragomann They are all set to any already. that was my exact thinking get them up and then tighten them down once they were up.
  • VTI gateways not adding static routes in 24.03

    88
    0 Votes
    88 Posts
    22k Views
    O
    I thought I'd do some further testing with earlier versions of CE, specifically 2.6.0. I'm happy to report that 0.0.0.0/0 works identically to 2.7.2. That version was released in the beginning of 2022..
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.