• 2.4.1 IPSec Status -> Overview Page broken

    4
    0 Votes
    4 Posts
    1k Views
    DerelictD
    Known issue: https://redmine.pfsense.org/issues/8003 https://redmine.pfsense.org/issues/7856 https://redmine.pfsense.org/issues/6335
  • Traffic inexplicably not going through IPSEC despite matching SPs

    1
    0 Votes
    1 Posts
    442 Views
    No one has replied
  • IPsec ping interval

    2
    0 Votes
    2 Posts
    741 Views
    C
    Found it in /etc/pfSense-rc.
  • Is is possible to set up pfSense as a client for IKEv2?

    3
    0 Votes
    3 Posts
    1k Views
    V
    Oh, that's too bad. At least there's that yet to give me hope. Thanks!
  • Multiple Roadwarriors Phase 1

    8
    0 Votes
    8 Posts
    2k Views
    M
    I ended up manually editing /cf/conf/config.xml to achieve what I want, just copied the relative code and changed the ikeid in phase 1 and 2 and uniqid in phase 2 , after that I was able to use the  pfsense GUI again. I now can connect from android, windows, and apple devices using different authentication methods.
  • Is there anyway to iperf from one pfsense to another across an ipsec/vpn?

    2
    0 Votes
    2 Posts
    1k Views
    NogBadTheBadN
    https://forum.pfsense.org/index.php?topic=138987.msg761370#msg761370
  • Can't access internet when connected to VPN?

    5
    0 Votes
    5 Posts
    4k Views
    H
    @dobler: I figured it out. In my case it was a vpn configuration issue. Make sure in phase 2 that you use 0.0.0.0/0 for local network if you want to access traffic outside. Just want to say I found this thread on Google and after searching for like 2 hours this is what fixed my problem.
  • Celeron J1900 only pushing 125Mbps over IKEv2 IPSec?

    9
    0 Votes
    9 Posts
    2k Views
    J
    @NogBadTheBad: Just had a play you can bind iperf to an ip address via the console using -B [2.4.1-RELEASE][admin@pfSense-vm1.localdomain]/root: iperf -B 10.0.1.1 -c 10.0.2.1 –---------------------------------------------------------- Client connecting to 10.0.2.1, TCP port 5001 Binding to local address 10.0.1.1 TCP window size: 64.2 KByte (default) [  3] local 10.0.1.1 port 2344 connected with 10.0.2.1 port 5001 [ ID] Interval      Transfer    Bandwidth [  3]  0.0-10.0 sec  152 MBytes  127 Mbits/sec [2.4.1-RELEASE][admin@pfSense-vm1.localdomain]/root: [2.4.1-RELEASE][admin@pfSense-vm2.localdomain]/root: iperf -B 10.0.2.1 -s –---------------------------------------------------------- Server listening on TCP port 5001 Binding to local address 10.0.2.1 TCP window size: 63.7 KByte (default) [  4] local 10.0.2.1 port 5001 connected with 10.0.1.1 port 2344 [ ID] Interval      Transfer    Bandwidth [  4]  0.0-10.0 sec  152 MBytes  127 Mbits/sec I get "Can't assign requested address" if I try that.
  • [HALF-SOLVED] About Phase 2 multiple subnets: packets routings.

    2
    0 Votes
    2 Posts
    972 Views
    BabizB
    Really this is not a IPsec VPN problem, VPN Itself working good because I see ICMP packets travels from one interface side to other interface side at the end of tunnel. Yesterdat I'll figured it out because when I added NAT portfowarding rule on IPsec  and virtual IP om MODEM interface for ICMP, then after commit I glad to see ping travel back on my admin pc station. ICMP packets roadmap like below: from 192.168.2.236 ping to 192.168.0.1 > echo request routed at  192.168.2.1 (pfSense gateway) under VPN tunnel. from remote pfSense router  VPN enpoint  the echo request route to 192.168.0.1 but for a kind of  behavior  I dont'know the port fowarding nat rule translate ICMP ECHO request from 192.168.2.236 to 192.168.0.99 at the MODEM interface. Packets ICMP ECHO request now will end to 192.168.0.1. and it will reply correctly sending ICMP ECHO reply back to 192.168.0.99. So at this point pfSense router I guess made auto rule for NAT  back the ICMP ECHO reply  to my admin station 192.168.2.236 previously triggered by NAT portfowarding. This works only with ICMP traffic type, TCP traffic not work ame as I described. I just decided to write new thread under NAT forum section for sekking to figure out enough about NAT LAN TO LAN translation for IP address, I guess to do with 1:! NAT But I'm not fully understand how it works at this time. https://forum.pfsense.org/index.php?topic=139240.0 A side note, I unable to dump, (packet capture) the ICMP traffic under MODEM interace + NAT portfowarding rule. simply  all left blank!! this is very strange for my opinion.
  • Version 2.4.1 Breaks IPsec Status Screen ?

    4
    0 Votes
    4 Posts
    981 Views
    ExordiumE
    @barnettd: I thought it might be a cache or browser issue, but its the same in IE, Chrome, and Firefox. Anyone else experiencing this? Confirmed. -> https://forum.pfsense.org/index.php?topic=139163.0
  • VPN set up, can ping and SSH LAN devices, but not view web interfaces

    1
    0 Votes
    1 Posts
    478 Views
    No one has replied
  • L2TP VPN

    2
    0 Votes
    2 Posts
    806 Views
    E
    It is quite a complex thing to do if you are not used to IT.  Have you followed the L2TP instructions in the PFSense Book?  If you buy that or can get it for free with your hardware, then try that first.  The full instructions are in it, apart from a single crucial step which is undocumented, and that is to allow your network to accept PING.  https://forum.pfsense.org/index.php?topic=1933.0
  • Frequent Disconnects With IPSec VPN Connection to Azure on 2.3.3

    18
    0 Votes
    18 Posts
    12k Views
    F
    It's been running stable for me since I made those changes referenced previously in this thread.
  • 0 Votes
    1 Posts
    445 Views
    No one has replied
  • IPsec site-to-site slow in one direction

    2
    0 Votes
    2 Posts
    812 Views
    S
    suggest we remove this from IPsec. I'll repost in hardware - turns out my entire inbound traffic stream is limited to 1.2mbs and it has nothing to do with the VPN.
  • Sending DNS search list to Mac OS broken?

    1
    0 Votes
    1 Posts
    302 Views
    No one has replied
  • Slow IPsec throughput

    1
    0 Votes
    1 Posts
    802 Views
    No one has replied
  • IPSec in 2.4.1 and 2.4.2

    1
    0 Votes
    1 Posts
    649 Views
    No one has replied
  • HELP! Possible pfsense bug parsing a CA certificate

    3
    0 Votes
    3 Posts
    759 Views
    M
    @jimp: Looks like this issue: https://redmine.pfsense.org/issues/7929 Having the same component with multiple values is tripping up that section of code, apparently. I don't have time to look into that one today, but it doesn't look too hard to solve, I can check it out next week though. The workaround from the bug above did it. Now it works, thank you very much. Hope this bug gets patched on next release. Best regards.
  • Better GUI support for IPSec Phase 1 proposals

    3
    0 Votes
    3 Posts
    662 Views
    O
    I hit something similar today. I dont have an answer, but it got me wondering if the config.xml has a defined schema ? Maybe there are additional parameters that can be manually defined in the xml ? I have been unable to find a schema so far.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.