• IPSEC pfsense<->cisco asa multiple phase2

    11
    0 Votes
    11 Posts
    9k Views
    B
    Use check box in P1:  Enable this to split connection entries with multiple phase 2 configurations. Required for remote endpoints that support only a single traffic selector per child SA.
  • PfSense sends wrong or corrupted data

    1
    0 Votes
    1 Posts
    480 Views
    No one has replied
  • NAT over IPsec with Draytek (possible?)

    2
    0 Votes
    2 Posts
    729 Views
    J
    This is possible with both DrayTek and pfSense, however I assume by now you have resolved the issue!
  • Route all Traffic / No "Remote Network" in Phase2

    2
    0 Votes
    2 Posts
    674 Views
    S
    push :X
  • PfSense IPsec FreePBX no audio times out after 30 seconds

    2
    0 Votes
    2 Posts
    662 Views
    ?
    I'm really not a VoIP guru, but whenever I have this behavior (calls dropped after a time-out), it is when there is a wrong NAT behavior somewhere.  The PBX side would be receiving packets where the source IP at network & transport layer doesn't match the IP declared at the SIP application layer Could it be that it was working before because your PBX setting was "easy" and therefore you were not noticing this NAT issue? Can you check on the PBX to see the source IPs of the stations registering, and check the tables for the registered extensions, and see if there is a match?
  • HELP ME: IKEv2 setup with StrongSwan server

    4
    0 Votes
    4 Posts
    2k Views
    ?
    I've done OpenVPN to NordVPN (I've even played around with 4 tunnels and load-balancing on the 4 tunnels) But haven't been able to configure IKEv2 towards NordVPN.  I read the guides you mentionned, but from what I read, MSCHAP can be configured for an IKEv2 server on pfSense, not an IKEv2 client on pfSense.  The guide on IKEv2 that you linked to is written for a IKEv2 server on pfSense, and remote clients like IOS or Android. Here's what I did: download root certificate from NordVPN convert to PEM format import as a CA in System->Certificate Go to VPN->IPSec and setup a sit to site tunnel. However, in the authentication box, either I see "Shared PSK" or "RSA" I have tried both settings, selecting the Root NordVPN cert for the remote in the "RSA" mode, or using my NordVPN password as the pre-shared-key when in "PSK" more When I go to the status page, and click "connect", it goes back to the "disconnected" state almost instantly.  When I check the logs, I keep getting an authentication failed reply from the NordVPN server. I might be missing something, though  :o
  • IPSec Tunneling Between 3 Different Sites

    7
    0 Votes
    7 Posts
    1k Views
    H
    My goal is the network from Site A (10.1.1.x/24) able to reach the network at Site C (10.3.3.x/24) regardless the traffic from A will be NAT to site B and will carry the IP Site B (10.2.2.x/24) instead. Also the same for Site C whereby it will carry the Site B IP in order to communicate with network on Site A. Site A (10.1.1.x/24)<–---------> Site B (10.2.2.x/24) <-----------> Site C (10.3.3.x/24)                               IPSEC & NAT                              IPSEC & NAT Probably the above illustration perhaps may give you some idea. Thank you in advance.
  • IPSEC VPN NOT CONNECTING AFTER UPGRADE

    1
    0 Votes
    1 Posts
    468 Views
    No one has replied
  • Make ipsenc tunnel using gateway Group as local interface

    1
    0 Votes
    1 Posts
    479 Views
    No one has replied
  • IPsec VPN between pfsense and zyxel NSG (nebula gateway)

    1
    0 Votes
    1 Posts
    673 Views
    No one has replied
  • VPN for Alcatel pbx

    1
    0 Votes
    1 Posts
    571 Views
    No one has replied
  • MOVED: Certificate Name Error OpenVpn

    Locked
    1
    0 Votes
    1 Posts
    313 Views
    No one has replied
  • Pfsense with SDNv2 in SCVMM 2016

    1
    0 Votes
    1 Posts
    943 Views
    No one has replied
  • 0 Votes
    1 Posts
    492 Views
    No one has replied
  • IPhone ipsec mutual psk vs mutual psk + xauth problems

    1
    0 Votes
    1 Posts
    544 Views
    No one has replied
  • Sites cannot reach each other, but mobileclients can reach both

    1
    0 Votes
    1 Posts
    378 Views
    No one has replied
  • Mac Split DNS issue

    2
    0 Votes
    2 Posts
    594 Views
    J
    Had a look at the file /usr/local/etc/strongswan.conf using grep "28675" strongswan.conf | hexdump -C and it looks like it just puts a newline at the end of the line so can't imagine this is a pfsense bug. 00000040  4c 45 41 56 45 4d 45 48  45 52 45 0a              |LEAVEMEHERE.| 0000004c Any suggestions to try and work out where the bug is ?
  • Issue with Ipsec Phase 2

    1
    0 Votes
    1 Posts
    492 Views
    No one has replied
  • L2TP over IPSec for iOS with v2.3.4

    3
    0 Votes
    3 Posts
    2k Views
    V
    Because we don't want to use certificates on clients like iOS. Authentication should be based on Windows AD only. When we need to use certificates, we can also use OpenVPN which we are testing at the moment. But also there I got stuck, cause I can't reach devices in LAN, but I created a post in the OpenVPN category for that case.
  • Define exceptions to Phase 2 tunnel policy?

    1
    0 Votes
    1 Posts
    422 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.