• Loosing connectivity when adding an IPSec Tunnel

    1
    0 Votes
    1 Posts
    440 Views
    No one has replied
  • IPSEC Tunnels restarting when adding VLAN or interfaces?

    4
    0 Votes
    4 Posts
    956 Views
    JeGrJ
    Yeah thought about that, but then I encountered a reset of all IPSec tunnels after just adding a CARP VIP on a fully independent new VLAN that isn't physically or logically envolved with any of the tunnels. Just adding the VIP brought down all IPSec tunnels. Seems kinda strange to me.
  • Deleted IPsec still trying to connect

    3
    0 Votes
    3 Posts
    831 Views
    R
    Hi, thank you for your reply! I rebooted twice and still in log and in ipsec showall. There is no entry in the config.xml of that last client anymore. Reboot didn't´t help :/ Any more ideas?
  • Pfsense traceroute hop unreachable through IPSEC

    1
    0 Votes
    1 Posts
    541 Views
    No one has replied
  • IPSec tunnel with Public IP interesting traffic and NAT

    1
    0 Votes
    1 Posts
    490 Views
    No one has replied
  • Scripting an IPSEC tunnel

    1
    0 Votes
    1 Posts
    464 Views
    No one has replied
  • Site-2-Site Redundant tunnel from PFSENSE to one location

    1
    0 Votes
    1 Posts
    421 Views
    No one has replied
  • IPSEC and NAT Spoofing farside networks

    1
    0 Votes
    1 Posts
    421 Views
    No one has replied
  • IPSec VPN - Zyxel to pfSense works but pfSense to Zyxel fails

    3
    0 Votes
    3 Posts
    2k Views
    T
    Update #2 This issue is still unresolved. However, I was able to properly configure the Zyxel to auto connect (its incoming VPN) whenever it determines that a connection is required. I would still appreciate if any suggestions can offered on why the pfsense can't connect to the zyxel but the zyxel can connect to the pfsense.
  • 0 Votes
    2 Posts
    633 Views
    K
    Have you enable traffic to flow in the firewall rules? There is a separate FW rules section for IPSec channels.
  • A question regarding IPsec rules for VPN (i'm new to PFSense)

    1
    0 Votes
    1 Posts
    857 Views
    No one has replied
  • Cannot route IPSec back out to internet (iOS)

    1
    0 Votes
    1 Posts
    809 Views
    No one has replied
  • (Probably Guide): IKEv2 with Windows 10 and better Security

    6
    0 Votes
    6 Posts
    5k Views
    T
    :-[ just realised I'm doing this on a test pfSense, not my live one so the IP address I was trying to ping was wrong. Once the VPN is active I can ping the test pfSense box and a client in that IP Range. Connect seems stable for the last few minutes. Couple of queries… Should I be able to ping the VPN user from the LAN or pfSense box ? I can't. When the VPN is connected the VPN user doesn't have internet access. If I remove the 'use default gateway on remote computer' then they do get Internet access but nothing across the VPN. Is it possible to have VPN traffic go across the VPN, but other traffic go out via the VPN users own Internet ? Thanks
  • Mac can´t connect to VPN with IKEv2 with EAP-MSCHAPv2

    3
    0 Votes
    3 Posts
    5k Views
    C
    Thanks jimp. This answer helped me resolve our issues with Mac's not being able to connect (and also Windows clients needing to disable the EKU check). When I created the Server Certificate initially I had used one address in the Common Name and a different one in the Subject Alternate Name. I created a new key with the Common Name and SAN matching (in System > Cert. Manager > Certificates) and then changed the certificate being used in the Mobile IPSec Phase 1 entry (VPN > IPSec > Tunnels > - Edit the Mobile IPSec Phase 1 entry - My Certificate). Everything now works perfectly for both Mac and Windows (without the registry setting change). Much appreciated. Perhaps it's worthwhile providing some more info in the documentation about why the IKE auth error occurs as well as providing the EKU Check registry hack to get around it. Thanks again, we can now move from PPTP over to a secure VPN technology. :)
  • Ipsec vpn to pfsense and internet = ok , but no traffic to nas

    1
    0 Votes
    1 Posts
    671 Views
    No one has replied
  • L2TP/IPSec: Blocked traffic

    1
    0 Votes
    1 Posts
    768 Views
    No one has replied
  • VPNs Problems with Cisco and 2.3.2-RELEASE

    2
    0 Votes
    2 Posts
    923 Views
    T
    I maybe facing these same errors. Does the connection work if you attempt to connect from the Cisco firewall?
  • What are best options for dynamic dns for multi-WAN IPsec failover?

    1
    0 Votes
    1 Posts
    562 Views
    No one has replied
  • IKEv2 - Phase 2 Auth Methods - Hash algorithmus Question

    2
    0 Votes
    2 Posts
    2k Views
    L
    An unmodified Windows up until 10 can use the following for Phase 2 (ESP): ESP:AES_CBC_256/HMAC_SHA1_96/NO_EXT_SEQ, ESP:3DES_CBC/HMAC_SHA1_96/NO_EXT_SEQ As you can see there is no option for SHA256 at this place to choose. It is questionable if this is a real problem because SHA1 is used for integrity in this context, so the upmost would be to send invalid (random) data which claim to be valid. The encryption (confidentialy) should not be broken because of this. You might also try the NegotiateDH2048_AES256 registry key to get more modern ciphers to choose from. Regards Andreas
  • Ipsec site to site udp stream lost pakets

    6
    0 Votes
    6 Posts
    1k Views
    R
    did we have any other idea?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.