• IPsec blocked In Egypt

    2
    0 Votes
    2 Posts
    871 Views
    DerelictD
    Short of moving out of Egypt, probably not.
  • Issues with AWS IPSec when accessing from UAE

    1
    0 Votes
    1 Posts
    409 Views
    No one has replied
  • ipsec.conf not updating

    5
    0 Votes
    5 Posts
    844 Views
    F
    Thank you! deleting P1/P2 and recreating them works now.
  • 0 Votes
    3 Posts
    2k Views
    L
    Thx - I just registered with redmine and posted a new bug report ticket: https://redmine.pfsense.org/issues/8549
  • Having issues with Azure IPSec Connection

    3
    0 Votes
    3 Posts
    1k Views
    DerelictD
    @livestrong2109 said in Having issues with Azure IPSec Connection: Jun 1 05:08:08 charon 14[CFG] <7> received proposals: The other side IKE:AES_CBC_256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024, IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024, IKE:AES_CBC_128/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024, IKE:3DES_CBC/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024 Jun 1 05:08:08 charon 14[CFG] <7> configured proposals: Your side IKE:AES_GCM_16_256/PRF_HMAC_SHA1/MODP_1024 Jun 1 05:08:08 charon 14[IKE] <7> received proposals inacceptable You are forcing AES GCM in the Phase 1 and the other side wants AES CBC (or 3DES). Based on what the other side is presenting I would probably select AES 256 and SHA256. [image: 1528272338840-screen-shot-2018-06-06-at-1.04.44-am-resized.png] Jun 1 05:08:08 charon 14[CFG] <7> no acceptable ENCRYPTION_ALGORITHM found Jun 1 05:08:08 charon 14[CFG] <7> selecting proposal: Jun 1 05:08:08 charon 14[CFG] <7> no acceptable ENCRYPTION_ALGORITHM found Jun 1 05:08:08 charon 14[CFG] <7> selecting proposal: Jun 1 05:08:08 charon 14[CFG] <7> no acceptable ENCRYPTION_ALGORITHM found Jun 1 05:08:08 charon 14[CFG] <7> selecting proposal: Jun 1 05:08:08 charon 14[CFG] <7> no acceptable ENCRYPTION_ALGORITHM found Jun 1 05:08:08 charon 14[CFG] <7> selecting proposal: Jun 1 05:08:08 charon 14[CFG] <7> no acceptable ENCRYPTION_ALGORITHM found Jun 1 05:08:08 charon 14[CFG] <7> selecting proposal: Jun 1 05:08:08 charon 14[CFG] <7> no acceptable ENCRYPTION_ALGORITHM found All of that is probably Azure attempting PFS groups you don't have defined. Probably more secure than PFS group 2.
  • how to disable nat-t for ipsec?

    2
    0 Votes
    2 Posts
    2k Views
    DerelictD
    You can't disable it if NAT is anywhere in what would be the ESP path. There are automatic rules for IPsec tunnels as most people who define an IPsec tunnel want IKE, ESP, and NAT-T to pass between the endpoints. You can disable these rules in System > Advanced, Firewall & NAT, Disable Auto-added VPN rules
  • 0 Votes
    2 Posts
    756 Views
    S
    An update: Changing the Shrewsoft setting on the Authentication tab for "Local Identity" from "Key Identifier" (which worked for the last several years) to UFQDN (using the same string) fixed the issue for me. I consider myself lucky to have found this, but maybe it makes sense to others. Thanks to anybody who gave this some thought. :-) SJ
  • L2TP/IPSEC VPN from multiple NAT IPs

    1
    0 Votes
    1 Posts
    368 Views
    No one has replied
  • 2.3.5 and 2.1.5 IPSec tunnel

    1
    0 Votes
    1 Posts
    305 Views
    No one has replied
  • VTI support eventually?

    6
    0 Votes
    6 Posts
    1k Views
    J
    @awebster thanks. As noted, it’s coming to 2.4.4.
  • 0 Votes
    12 Posts
    6k Views
    jimpJ
    FYI- We are making progress on IPsec VTI which will let this work. It should be in snapshots in the next week or so.
  • Pfsense and ftp on vpn in IPSEC

    1
    0 Votes
    1 Posts
    438 Views
    No one has replied
  • IPSec tunnel is up, but can not ping the remote site (network)

    1
    0 Votes
    1 Posts
    454 Views
    No one has replied
  • IKEv2 and WPA2-Enterprise with EAP-RADIUS on Win10 1607\. Finally working!

    12
    0 Votes
    12 Posts
    5k Views
    S
    @TMA-3: I'm curious - is this a Microsoft problem or a pfSense problem?  Both? I'm a little concerned that I've created an installation that will break at the next upgrade, but I hope ECDSA support will be added soon so I don't have to worry. Thanks again for sharing all this information - it is invaluable! Sorry I haven't replied soon, I had some issues in the last months and I had very little time to connect to anything. I'm pretty sure it's a microsoft issue and specific with IKEv2. IKEv1 works perfectly with fragments. Probably (and hopefully) next versions will fix it. FYI, it's very possible to fix the ECDSA even on latest version. I tested it this week. I'll update this post soon using public certificates from letsencrypt.
  • Force certain traffic over IPsec

    1
    0 Votes
    1 Posts
    337 Views
    No one has replied
  • GRE is not being encapsulated

    2
    0 Votes
    2 Posts
    663 Views
    M
    So I found when it occur, after you first time create a gre over ipsec everything works great, but after reboot it created GRE, and then IPsec, so GRE is not being encrypted. Is it a bug?
  • Confused: RADIUS server certs

    1
    0 Votes
    1 Posts
    437 Views
    No one has replied
  • VPN L2TP/IPSEC

    1
    0 Votes
    1 Posts
    640 Views
    No one has replied
  • Mobile ipsec client reauthentication

    2
    0 Votes
    2 Posts
    639 Views
    L
    Looks like NAT and reauthentication is giving this issue in a certain case. The clients will start to get double virtual ip's if the NAT device expires/reboots/crashes. If I disable reauthentication on both sides it solves the issue. I still can't explain why this works but for me it looks like it could be a bug in strongswan. It's 100 percent reproduceable with the follow setup RW(client) -> Pfsense(nat) -> Pfsense(endpoint) Rebooting the NAT will give double virtual ip's to the RW where one of the ip given doesn't work
  • IPSEC / CARP - Re-Keys on failover

    1
    0 Votes
    1 Posts
    328 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.