• Phase 2 question

    5
    0 Votes
    5 Posts
    924 Views
    jimpJ
    Aliases won't work there. You will either have to make each combination of P2 or, if the subnets are next to each other and line up nicely, summarize them with a larger mask. If you can provide some more detail about the networks (even just the last 2-3 octets), perhaps we can offer some suggestions about how to craft the P2s
  • [SOLVED] 2 IPSec tunnels with same remote network

    5
    0 Votes
    5 Posts
    1k Views
    M
    Thanks a lot for your help !
  • "peer requested EAP, config inacceptable" with IKEv2 and EAP-RADIUS

    9
    0 Votes
    9 Posts
    12k Views
    G
    @j@svg: Logs: Log entries Dec 16 11:51:20 charon: 16[NET] <bypasslan|1> sending packet: from  216.x.x.x[4500] to  215.x.x.x[61443] (68 bytes) Dec 16 11:51:20 charon: 16[ENC] <bypasslan|1> generating IKE_AUTH response 1 [ N(AUTH_FAILED) ] Dec 16 11:51:20 charon: 16[IKE] <bypasslan|1> peer supports MOBIKE Dec 16 11:51:20 charon: 16[IKE] <bypasslan|1> received ESP_TFC_PADDING_NOT_SUPPORTED, not using ESPv3 TFC padding Dec 16 11:51:20 charon: 16[CFG] <bypasslan|1> no alternative config found Dec 16 11:51:20 charon: 16[IKE] <bypasslan|1> peer requested EAP, config inacceptable Dec 16 11:51:20 charon: 16[CFG] <bypasslan|1> selected peer config 'bypasslan' Dec 16 11:51:20 charon: 16[CFG] <1> looking for peer configs matching  216.x.x.x[ 216.x.x.x]... 215.x.x.x[192.168.125.2] Dec 16 11:51:20 charon: 16[ENC] <1> parsed IKE_AUTH request 1 [ IDi N(INIT_CONTACT) N(MOBIKE_SUP) IDr CPRQ(ADDR DHCP DNS MASK ADDR6 DHCP6 DNS6) N(ESP_TFC_PAD_N) N(NON_FIRST_FRAG) SA TSi TSr ] Dec 16 11:51:20 charon: 16[NET] <1> received packet: from  215.x.x.x[61443] to  216.x.x.x[4500] (316 bytes) Dec 16 11:51:20 charon: 16[NET] <1> sending packet: from  216.x.x.x[500] to  215.x.x.x[30930] (353 bytes) Dec 16 11:51:20 charon: 16[ENC] <1> generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) CERTREQ N(MULT_AUTH) ] Dec 16 11:51:20 charon: 16[IKE] <1> sending cert request for "C=US, ST=Missouri, L=Kansas City, O=Corp, OU=Information Technology, CN=svg-ec-ca, E=info@xxx.com" Dec 16 11:51:20 charon: 16[IKE] <1> sending cert request for "C=US, ST=Missouri, L=Kansas City, O=Corp, OU=Information Technology, CN=svg-eap-ec-ca, E=info@xxx.com" Dec 16 11:51:20 charon: 16[IKE] <1> remote host is behind NAT Dec 16 11:51:20 charon: 16[IKE] <1>  215.x.x.x is initiating an IKE_SA Dec 16 11:51:20 charon: 16[ENC] <1> parsed IKE_SA_INIT request 0 [ SA KE No N(REDIR_SUP) N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) ]</bypasslan|1></bypasslan|1></bypasslan|1></bypasslan|1></bypasslan|1></bypasslan|1></bypasslan|1> Any help much appreciated! I've encountered this before in my testing although I can't remember specifically what I did for this particular condition. Take a look at the Phase 1 and Phase 2 settings in this doc: https://forum.pfsense.org/index.php?topic=127457.0
  • Windows 10 IPsec IKEv2 connection with standard Microsoft VPN Client

    16
    0 Votes
    16 Posts
    46k Views
    G
    See this posting for a new updated IKEv2 EAP-MSCHAP document that works with BOTH Windows 10 AND OSX. https://forum.pfsense.org/index.php?topic=127457.0 It combines some of the stuff in this thread in one place. Hope it helps.
  • IPSec tunnel gets established but then drops after 15 seconds

    1
    0 Votes
    1 Posts
    624 Views
    No one has replied
  • Pfsense 2.3.2 VPN to FritzBox 7490 06.60

    8
    0 Votes
    8 Posts
    12k Views
    C
    Hi guys I have a similar problem connection is active but traffic exchange impossible how you want to configure PfSense for traffic exchange ??? thx
  • IPSec fails with "no shared key found for '%any'"

    2
    0 Votes
    2 Posts
    12k Views
    J
    I fixed this by switching the remote Peer ID to something other than Key ID; I used Distinguished Name and set it to the dynamic DNS hostname for the remote site
  • Add Ipsec Road warriors idle timeout

    1
    0 Votes
    1 Posts
    466 Views
    No one has replied
  • IPSEC initiator - automatically re establish connection. ?

    2
    0 Votes
    2 Posts
    711 Views
    W
    Hello, I'm a newbie on pfSense but I had the same question ! I mock up a platform for a client and when I practice an interruption, the VPN IPSec don't go back up. Do you find a solution ? Regards, W.
  • [SOLVED] Connect to IPsec from local WLAN

    4
    0 Votes
    4 Posts
    6k Views
    P
    Hello Stefani, I have the same issue as you have seen in https://forum.pfsense.org/index.php?topic=126332.0 My question, did you resoved the issue? For me it is not really clear, wheter you can connect from internal LAN now? Thanks, Perino
  • 0 Votes
    3 Posts
    746 Views
    R
    @jecrabtree: What rules are assigned in IPSEC on both sides? On the Meraki side I just put in the PSK and the subnet that would be on this side.  This tunnel worked to a previous Meraki box and to a watchguard box. I matched up the IPSec settings and my SPDs look good.  Just no traffic flows.
  • 0 Votes
    1 Posts
    631 Views
    No one has replied
  • IPSEC NAT/Binat with routed subnets not Natting or passing traffic

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    J
    Got it solved. Ended up being a configuration in the Traffic Shaper. I had HFSC configured on all the interfaces. However after adding the new interface I did not copy the settings into the new interface. I clicked the remove shaper and the second that happened all traffic was flowing correctly. I then did the Multi all wizard and at that time it wouldnt compelte without throwing an error about a speed mismatch. This particular interface is 100MB however the WAN interface has a lot more. This was the only thing I could see as the issue. After some TLC the shaper is back in without errors and traffic is still flowing. I have seen this before on other HFSC implementation either from an interface being added, or upgrade causing traffic to just stop being passed, even if the rule has no queues being set the matched traffic just doesnt work. Anyway. If your reading this and have HFSC setup and seeing a similair issue. Go ahead and remove it to see if that corrects it. you'll likely find the issue when you attempt to run the wizard again as it will likely not complete and load the rules without an error, at least in my case that was it. As for the setup. There is a LAN Core onsite at teh main office that detours specific matching traffic to the P2P Core that is in a rack at a datacenter offsite. That P2P core will either send the traffic to one of the  multiple sites or to the Interface on the PFSENSE FW in the DataCenter. This was the FW we experienced the problem from. (Cores are Layer 3 switches performing Routing functions for sites or intervlan traffic)
  • IPSec connection attempt isn't blocked.

    3
    0 Votes
    3 Posts
    658 Views
    P
    @zMaliz: Why doesn't this stop the connections ? Because when configuring a VPN, hidden firewall rules are automatically added to allow the corresponding traffic in. I would assume that you allow mobile clients in as then the source address of the above mentioned hidden rules is set to any. You could disable these VPN rules from being automatically created (System, Advanced, Firewall and NAT, Disable Auto-added VPN rules) but then you'd have to manually add your own rules on the WAN interface to allow the legitimate IPsec traffic.
  • Cant connect to internet via IPSEC

    1
    0 Votes
    1 Posts
    430 Views
    No one has replied
  • IPSec VPN connection from internal LAN

    2
    0 Votes
    2 Posts
    1k Views
    S
    I've got the same issue: https://forum.pfsense.org/index.php?topic=123650.0 So far no solution found.
  • Blackhole Remote Network addresses if tunnel is down

    3
    0 Votes
    3 Posts
    1k Views
    J
    That is a sweet solution, thank you! I searched the pfSense Book earlier for Egress filtering, thinking I could filter on outbound from an interface someplace, but didn't find it.  Didn't realize you could specify direction on Floating rules.  Thanks again!
  • Remotely access LAN with UDP autodiscover for media devices

    1
    0 Votes
    1 Posts
    460 Views
    No one has replied
  • Version 2.3 IPSec both sides

    7
    0 Votes
    7 Posts
    2k Views
    4
    I have the same no ike error when I configured for carp ipsec mschapv2 for win8/10 as seen in https://www.youtube.com/watch?v=xV1vEl4XAnw but did not changed WAN IP for WAN CARP IP
  • Connecting to Cisco ASA - Dual WAN

    1
    0 Votes
    1 Posts
    550 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.