• Routing selective outbound NAT traffic through IPSEC

    2
    0 Votes
    2 Posts
    476 Views
    DerelictD

    OpenVPN will be a lot more flexible for that.

  • Routing specific /24 over ipsec

    2
    0 Votes
    2 Posts
    448 Views
    DerelictD

    That's because you cannot policy route IPsec like you can OpenVPN.

    You might be able to use a phase 2 of 10.47.5.0/24 <-> 0.0.0.0/0 with the reciprocal on the other side, but OpenVPN is a lot more flexible in this regard.

  • IPSEC performance? tinc?

    1
    0 Votes
    1 Posts
    764 Views
    No one has replied
  • Mobile client to home network w/ access to remote site-to-site network

    2
    0 Votes
    2 Posts
    443 Views
    M

    I think we want to do the same thing ish
    https://forum.pfsense.org/index.php?topic=144475.0

  • How to configure VPN Client l2tp/ipsec with PFsense

    3
    0 Votes
    3 Posts
    12k Views
    S

    Windows clients use 3DES for the encryption, use 3DES in the phase 1 of the IPSec tunnel instead of AES.

    Source:
    https://support.microsoft.com/en-ca/help/325158/default-encryption-settings-for-the-microsoft-l2tp-ipsec-virtual-priva

  • Only 1 IPSec VPN Tunnel Can be UP at a Time

    21
    0 Votes
    21 Posts
    2k Views
    S

    Thanks Buddy

  • Pfsense –> Juniper SRX 240 - NAT / BINAT translation

    1
    0 Votes
    1 Posts
    453 Views
    No one has replied
  • IPSec Tunnel Granting One Way Traffic

    2
    0 Votes
    2 Posts
    309 Views
    DerelictD

    Firewall rules on the IPsec tab on pfSense?

  • VPN IS down after a time period

    3
    0 Votes
    3 Posts
    548 Views
    S

    I have the same problem right now…all works until they start dropping like flies and won't reconnect!

  • Direct traffic in IPSECVPN Site to Site "Phase 2 Tunnels"?

    5
    0 Votes
    5 Posts
    613 Views
    I

    That worked!!! Thank you very much.

  • [SOLVED] cross platform IKEv2 VPN - no DNS on Linux/Mac/IOS

    7
    0 Votes
    7 Posts
    12k Views
    T

    @shpokas:

    I fixed the DNS issue on OS X and IOS by using Apple Configurator to create VPN profile and manually adding DNS section in it.
    Here's how to do it: https://lists.strongswan.org/pipermail/users/2015-October/008842.html

    This is definitely the key for split DNS with macOS and iOS!  More details can be found in Apple's Configuration Profile Reference https://developer.apple.com/library/content/featuredarticles/iPhoneConfigurationProfileRef/Introduction/Introduction.html#//apple_ref/doc/uid/TP40010206-CH1-SW612
    Look for the DNS Dictionary Keys section and it explains the use of SupplementalMatchDomains to control spilt DNS.  Not sure why this isn't available from the Configuration GUI, but… there you go.

  • No outgoing UDP traffic

    1
    0 Votes
    1 Posts
    464 Views
    No one has replied
  • VPN user group missing

    2
    0 Votes
    2 Posts
    1k Views
    D

    Answered my own question.  Below groups are effective permissions, you can add the permission to that for IPSEC Xauth dialin.

  • No matching peer config found

    1
    0 Votes
    1 Posts
    661 Views
    No one has replied
  • (Sort of off-topic) Connecting pfsense <-> Unifi USG

    5
    0 Votes
    5 Posts
    1k Views
    C

    Hey,

    I eventually (this friday) gave up. I even tried running openVPN on the USG directly (command line) which worked but the transfer speed was abyssmal slow. I installed a tiny Intel NUC (12 Watt) that does OpenVPN just fine with the pfsense. Even with double-Nat :)

    -Chris.

  • IPSec phase2 with NAT/BINAT both sides fails to communicate

    1
    0 Votes
    1 Posts
    375 Views
    No one has replied
  • Additional Details for IPSec Mobile Clients

    3
    0 Votes
    3 Posts
    606 Views
    J

    Thanks for the reply!
    I'm checking those tabs, and I only see the remote public IP, not the local IP that the client is receiving from pfsense.
    The scenario is, I'm rolling this out to a company of multiple users, and I would like to be able to identify each client on the router, but it seems like that info is obfuscated from me at this point.
    Appreciate your help!

  • SG-3100 IPSec –-

    3
    0 Votes
    3 Posts
    624 Views
    P

    One more part –

    Feb 7 14:07:00 charon 13[NET] <con1000|3>sending packet: from 172.16.200.20[500] to xxx.xxxx.xxx.x[500] (180 bytes) Feb 7 14:07:00 charon 13[NET] <con1000|3>received packet: from xxx.xxx.xxx.x[500] to 172.16.200.20[500] (160 bytes) Feb 7 14:07:00 charon 13[ENC] <con1000|3>parsed ID_PROT response 0 [ SA V V V V ] Feb 7 14:07:00 charon 13[IKE] <con1000|3>received XAuth vendor ID Feb 7 14:07:00 charon 13[IKE] <con1000|3>received DPD vendor ID Feb 7 14:07:00 charon 13[IKE] <con1000|3>received FRAGMENTATION vendor ID Feb 7 14:07:00 charon 13[IKE] <con1000|3>received NAT-T (RFC 3947) vendor ID Feb 7 14:07:00 charon 13[ENC] <con1000|3>generating ID_PROT request 0 [ KE No NAT-D NAT-D ] Feb 7 14:07:00 charon 13[NET] <con1000|3>sending packet: from 172.16.200.20[500] to xxx.xxxx.xxx.x[500] (244 bytes) Feb 7 14:07:00 charon 13[NET] <con1000|3>received packet: from xxx.xxx.xxx.x[500] to 172.16.200.20[500] (244 bytes) Feb 7 14:07:00 charon 13[ENC] <con1000|3>parsed ID_PROT response 0 [ KE No NAT-D NAT-D ] Feb 7 14:07:00 charon 13[IKE] <con1000|3>local host is behind NAT, sending keep alives Feb 7 14:07:00 charon 13[ENC] <con1000|3>generating ID_PROT request 0 [ ID HASH N(INITIAL_CONTACT) ] Feb 7 14:07:00 charon 13[NET] <con1000|3>sending packet: from 172.16.200.20[4500] to xxx.xxx.xxx.x[4500] (108 bytes) Feb 7 14:07:01 charon 13[NET] <con1000|3>received packet: from xxx.xxx.xxx.x[4500] to 172.16.200.20[4500] (92 bytes) Feb 7 14:07:01 charon 13[ENC] <con1000|3>parsed INFORMATIONAL_V1 request 907020096 [ HASH N(AUTH_FAILED) ] Feb 7 14:07:01 charon 13[IKE] <con1000|3>received AUTHENTICATION_FAILED error notify Feb 7 14:09:19 charon 00[DMN] signal of type SIGINT received. Shutting down</con1000|3></con1000|3></con1000|3></con1000|3></con1000|3></con1000|3></con1000|3></con1000|3></con1000|3></con1000|3></con1000|3></con1000|3></con1000|3></con1000|3></con1000|3></con1000|3></con1000|3>
  • IPsec Packet Loss, Dropped RDP Connections

    1
    0 Votes
    1 Posts
    439 Views
    No one has replied
  • Microtek and Pfsense Ipsec

    1
    0 Votes
    1 Posts
    449 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.