• HowTo create a Site-to-Site connection with my side in Subnet?

    1
    0 Votes
    1 Posts
    314 Views
    No one has replied
  • [IPSec] Unable to force all internet traffic over IKEv1 L2L

    6
    0 Votes
    6 Posts
    698 Views
    N

    Hello,

    It was indeed this Firewall Rule.

    Once I removed the Gateway part, traffic started hitting the IPSec tunnel.

    Cheers for the help.

  • Disable old ciphers

    2
    0 Votes
    2 Posts
    546 Views
    bepoB

    @gsmithe said in Disable old ciphers:

    SHA1

    Hey gsmithe,

    i don't now your PCI scanner. Sometimes a scanner alerts at SHA1 too.
    Check your Phase1/Phase2 config. If the configuration for DES/3DES is unchecked, this is not your problem.

    Kind regards

  • Pfsense - Parameter Tunnel GRE with IPSec

    1
    0 Votes
    1 Posts
    274 Views
    No one has replied
  • Multiple child SA entries (same tunnel)

    5
    0 Votes
    5 Posts
    2k Views
    blackpaw29B

    Same issue here, 2.4.3-1

  • IPsec Broken in Latest Dev 2.4.4.a.20180705.0739

    3
    0 Votes
    3 Posts
    621 Views
    M

    Many thanks!

  • IPSEC Tunnel works only when IP is static

    6
    0 Votes
    6 Posts
    685 Views
    E

    The tunnel only work when the IP in the server is set manually but only in the 40.0/24 segment, dynamically don't work. The segment 41.0/24 does not send traffic to pfsense at all, even when the /23 is set up in Phase 2. Due to Policies and Prod enviroments working in another tunnels i can update the version.

  • IPsec service very slow, sometimes timeouts

    3
    0 Votes
    3 Posts
    483 Views
    C

    During the problem, the Memory usage is about 6% of 8052MiB, the cpu usage is about 30%. In Idle mode the cpu usage is at 5-10% and the RAM at 6%.
    We also have a second system (same hardware) with 24 tunnels, applying changes there take just a second.

  • 0 Votes
    2 Posts
    803 Views
    bepoB

    @marcos-lang Could you please provide screenshots from your configuration and the ipsec status pages? Especially from SAD/SPD etc?

    The use of public IP in NAT (I believe not)? > This should work without problems.

    The difference in size of Local "real" and NAT'ed networks? > If you want to NAT your Local Network into a single ip you have to choose NAT/BINAT Type "Address" and NOT Network/32.

    Should I use /24 on NAT'ed networks and create a 1:1 relation on both ends? > No

    Should I create a VIP with the NAT'ed IP of Local Subnet (172.140.50.2/32)? > No

    Should I create a static route for the NAT'ed IP of Remote Subnet (172.140.60.2/32)? > No. Routing is ignored for IPSec

  • Issue with VTI and IPSEC (1nd July Snapshot) IKEv2 & ESP

    2
    0 Votes
    2 Posts
    602 Views
    jimpJ

    Seems very close. All of mine show RUNNING though. Make sure you have followed the proper procedure to not only create the tunnel but to assign it for use.

    https://www.netgate.com/docs/pfsense/vpn/ipsec/ipsec-routed.html

  • 0 Votes
    2 Posts
    388 Views
    K

    Specifically:

    found 1 matching config, but none allows pre-shared key authentication using Aggressive Mode

    If my P1 entry is doing Aggressive with PSK for the "My IP address" and "Peer IP address" and it matches my proposals for hash and encryption...why can't it recognize my PSK?

  • IPsec VPN Not Passing Traffic for iPhones/Macs

    3
    0 Votes
    3 Posts
    933 Views
    D

    For anyone running into this problem, after much digging I found this is actually a problem with Rogers cellular service. You need to call Rogers in the interim and have them blacklist your IMEI from using IPv6. They are working on a more permanent fix...I opened a ticket and am currently waiting for them to blacklist mine but details are at this Rogers community thread.

    http://communityforums.rogers.com/t5/Network-Coverage/Issues-with-IKEv2-IPSec-VPN-on-Rogers-LTE-3G/td-p/419136/page/8

    D

  • IPSEC VPN to Yamaha RTX-810 -- Some settings questions!

    2
    0 Votes
    2 Posts
    767 Views
    K

    I have found in the documentation that I should use "Any" rather than "any".

  • FW to FW IPSEC w/hardware AES failing

    1
    0 Votes
    1 Posts
    404 Views
    No one has replied
  • Not able to get tunnel up with Azure

    1
    0 Votes
    1 Posts
    329 Views
    No one has replied
  • IPSEC in Bridge Mode

    1
    0 Votes
    1 Posts
    523 Views
    No one has replied
  • chained ipsec tunnels and routing issues

    2
    0 Votes
    2 Posts
    402 Views
    jimpJ

    Every step needs P2 entries for every possible combination of traffic.

    On both sides of the tunnel from 1<->2, it needs P2s for 1-2 and 1-3. On both sides of the tunnel from 2<->3, it needs P2s for 2-3 and 1-3.

    Expanded a bit:

    Site 1 tunnel 1<->2 has P2s:

    Local 1 / Remote 2 Local 1 / Remote 3

    Site 2 tunnel 2<->1 has P2s:

    Local 2 / Remote 1 Local 3 / Remote 1

    Site 2 tunnel 2<->3 has P2s:

    Local 2 / Remote 3 Local 1 / Remote 3

    Site 3 tunnel 3<->2 has P2s:

    Local 3 / Remote 2 Local 3 / Remote 1
  • IPSec Status fill up with any any entries

    1
    0 Votes
    1 Posts
    347 Views
    No one has replied
  • IPsec tunnel mode with ASR

    1
    0 Votes
    1 Posts
    477 Views
    No one has replied
  • Site-to-site ipSec - route for pfsense server itself?

    4
    0 Votes
    4 Posts
    699 Views
    R

    Thanks for the info!

    I am wanting to setup remote logging to a device on the VPN network.
    I'll check out the link :)

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.