• StowngSwan ipsec and Screwsoft VPN panic

    13
    0 Votes
    13 Posts
    7k Views
    B
    For those who still have problem with Shrew VPN client and pfSense Mobile Client:  to make it work try the following settings in the Shrew client: a) General -> Auto Configuration -> ike config pull b) Phase 2 ( this is what  gives you the grief or at least what is being discussed in this topic) -> esp-aes / 256 / md5 / pfs - group 2 (can be any if set properly on both ends) and everything should work. If it does not, run Shrew VPN Trace ( a utility coming with the Shrew VPN) , change the debug log verbosity, you will get a log. Examine both logs (Shrew's one and pfSense's IPsec log and things should be more or less clear, you will see what is wrong). That's beyond me  why when I set up a site to site tunnel in Shrew  I can easily do that with manual configuration  and phase 2 settings mentioned in multiple pfSense tutorials: eso-aes / 256 / sha 1  But for  the mobile client pfSense requires  esp-aes / 256 / md5 - that is utterly strange. Over last 2 days I read a lot of posts on this forum and other places regarding Shrew VPN related problems. I guess it speaks  a volume. Anyway, I am glad that eventually I made it work.
  • IPSec -> How to push multiple routes?

    4
    0 Votes
    4 Posts
    1k Views
    A
    To answer (some of) my own questions: I chose a reboot https://forum.pfsense.org/index.php?topic=124304.0
  • Phase 2 question

    3
    0 Votes
    3 Posts
    983 Views
    A
    The second P2 (may have) needed a reboot to come up. It is now working successfully on the independent OPT1 subnet via IPsec. I tried a restart of the IPsec service, at both ends - that didn't help. A reboot, which presumably shouldn't have been necessary(?), did the trick. Hope this helps…
  • IPSec successful login but cannot connect to Local LAN

    1
    0 Votes
    1 Posts
    494 Views
    No one has replied
  • Traffic from openVPN to IPsec tunnel

    1
    0 Votes
    1 Posts
    571 Views
    No one has replied
  • Site2Site with mobile client connecting too

    1
    0 Votes
    1 Posts
    587 Views
    No one has replied
  • Ipsec starts flapping when I enable ipv6 on WAN

    1
    0 Votes
    1 Posts
    470 Views
    No one has replied
  • Packages not routed over IPSEC but going out on WAN

    11
    0 Votes
    11 Posts
    2k Views
    W
    SOLVED! After looking again I finally realised my phase 2 was 10.95.0.0/16 on one side and 10.95.00/23 on the other. That doesn't include 10.95.95.103…. So it is going to WAN instead. I'll have a second look on tcp/ip for dummies :( Sorry for the waste of time. What surprises me highly though is that a phase2 is established, even though there is a subnet mismatch. The SPD established is 10.95.00/23, likely because that fits in 10.95.0.0/16. I always understood that in case of a mismatch it would fail at all. In that case the cause was much more clear.
  • Ipsec ping works, http not

    3
    0 Votes
    3 Posts
    2k Views
    R
    oh damn this was the reason: Proxmox: IMPORTANT: Enter the web GUI and go in System > Advanced > Networking and flag Disable hardware checksum offload. If you don't do it layer3 traffic from lan to wan will not work, or will be really slow (but traffic to/from the firewall will work fine: see the pf sense wiki about virtio for details https://doc.pfsense.org/index.php/VirtIO_Driver_Support )
  • Which Correct MTU/MSS configuration

    3
    0 Votes
    3 Posts
    4k Views
    R
    By looking further, IPsec is generally not working well with NAT-T. I have many traffic drops. neither with multiple Phase2, Even if status shows tunnels online. Rebooting make tunnels work again for some time. I have changed NAT-T Tunnels with OpenVPN as i'm 100% pfsense on remote sites. Since it works much better. I have just trouble when rebooting server. I'll make a topic. Regards
  • Poor IPSEC performance

    1
    0 Votes
    1 Posts
    919 Views
    No one has replied
  • IPSEC in a failover setup.

    2
    0 Votes
    2 Posts
    513 Views
    dotdashD
    The backup node will not try to connect any tunnels until it switches to master.
  • IPSec just stopped working, no changes, not sure why.

    2
    0 Votes
    2 Posts
    797 Views
    DerelictD
    Yeah that is one second of logs that shows charon not taking action because it is waiting for another action to complete, which is perfectly normal. Going to need more logs than that. Set IKE SA, IKE Child SA, and Configuration backend logging to Diag and post them up. Sounds like an ISP might have done something.
  • Any way to use IPsec with macOS / iOS in main mode?

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Site-to-Site VPN: accept shared key for any IP

    3
    0 Votes
    3 Posts
    746 Views
    C
    @mikee: Hi. You are requesting to configure a dynamic endpoint. You should be able to achieve this by using 0.0.0.0 as the IP of the remote endpoint. This should allow ANY remote IP to connect. Anyway with this value the tunnel will only be able to be started from the remote side because we (the local side) do not know where to talk to. The VPN will be down until traffic from the remote side fires the VPN up. Cheers. How could I miss that, thank you very much!
  • Tunnel's failing to initialise on traffic

    1
    0 Votes
    1 Posts
    456 Views
    No one has replied
  • Mobile Warrior IPSEC VPN works with Android not with Shrewsoft

    4
    0 Votes
    4 Posts
    1k Views
    W
    Thank you, much appreciated. I'll continue to plug along.  My mobile phone has stopped connecting now for some reason, nothing in any settings has changed, just not connecting.  Rebooted PFsense, but no joy. When I have time, i'll look further into it. Thank you Willo
  • IPSEC between 2 pfsense 2.3.2 failed in Phase 1

    2
    0 Votes
    2 Posts
    2k Views
    M
    The logs are showing an authentication failure.
  • 0 Votes
    2 Posts
    2k Views
    M
    When you use certificates to validate a VPN the remote side must have a way to validate the received certificate so you must have the public key of the sender CA installed on it. Have you installed the certificate of the CA in the remote side?.
  • Mobile IPSEC 2.3.2_1 routing problem?

    2
    0 Votes
    2 Posts
    785 Views
    M
    To be able for the community to know if you missed something perhaps you could first post what your actual config is…. For what you say it looks like you have a hub mode config: ALL traffic is sent to the VPN when connected. But again, post your config or we all are blind.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.