• Routing Protocols on the IPSec Interface

    1
    0 Votes
    1 Posts
    772 Views
    No one has replied
  • PFSense IPSec <> Cisco RV042 almost there.

    2
    0 Votes
    2 Posts
    854 Views
    DerelictD
    @Bleumunkie: I have the VPN setup, connects. I can ping and connect to computers on the RV042 side from PFSense network, however I cannot ping or connect to computers on the PFSense network from the RV042. Any tips?  is this a firewall config or VPN config?? Impossible to know without more information. Did you pass the traffic on pfSense's Firewall > Rules, IPsec tab Those rules dictate what incoming connections will be allowed from IPsec remote sites/users.
  • Behind FW perimeter PFsense how VPN IPsec HUB

    1
    0 Votes
    1 Posts
    503 Views
    No one has replied
  • IPSec Service Stops

    1
    0 Votes
    1 Posts
    603 Views
    No one has replied
  • IPSec is going down every 24-48 hours help

    3
    0 Votes
    3 Posts
    3k Views
    B
    If I stop every ipsec connection and restart it yes. I see phase 1 and 2. Now I can say after 48 hours the vpn connection will crash. Yesterday I got these error messages: <con2 40="">failed to establish CHILD_SA, keeping IKE_SA After every reboot I have a error message: Crash report begins.  Anonymous machine information: amd64 10.3-RELEASE-p9 FreeBSD 10.3-RELEASE-p9 #1 5fc1b19(RELENG_2_3_2): Tue Sep 27 12:26:06 CDT 2016    root@ce23-amd64-builder:/builder/pfsense-232/tmp/obj/builder/pfsense-232/tmp/FreeBSD-src/sys/pfSense Crash report details: PHP Errors: [02-Dec-2016 04:01:23 Europe/Berlin] PHP Warning:  PHP Startup: Unable to load dynamic library '/usr/local/lib/php/20131226/suhosin.so' - /usr/local/lib/php/20131226/suhosin.so: Undefined symbol "ps_globals" in Unknown on line 0 at the moment I fixed my problem with a cron job. Every night at 4 a clock the the firewalls will reboot but this couldn`t be a solution.</con2>
  • IKEv2 VPN with EAP-RADIUS will not authenticate

    6
    0 Votes
    6 Posts
    35k Views
    N
    OK, I solved it. All indications on this error message were to do with a mismatch between the Radius settings in pfsense and the Radius client in NPS. No amount of changing the settings worked UNTIL, I rebooted the pfsense. I got the idea from a post I found about Watchguard firewalls (go figure! bsd based?) where you have to reboot the unit to effect changes to radius settings. After rebooting and adjusting my NPS Connection and Network Policies, the VPN connects and authenticates using domain credentials. One tip for anybody with Wireless Access Points authenticating to the same NPS. Create separate policies for IKEv2  auth and use the condition 'Client Friendly Name' and set this to same value as your Distinguished Name in the phase I settings. This will differentiate it from either your default or WifI PEAP policy and use MSCHAPv2 authentication.
  • Proxy ID mismatch between Juniper SSG and PFSense

    3
    0 Votes
    3 Posts
    3k Views
    J
    had this some times with SSGs if i allow them to choose between multiple proposes. it worked for me after i set up only one Proposal on both sites so the don't need to negotiate for this.
  • IPSEC as a Fallback for Directed Radio connection

    1
    0 Votes
    1 Posts
    502 Views
    No one has replied
  • Connection not staying up for long?

    2
    0 Votes
    2 Posts
    770 Views
    S
    I can't offer much in the way of support but I have noticed similar issues with IOS -> pfsense.
  • Issue with multiple phase 2

    7
    0 Votes
    7 Posts
    2k Views
    DerelictD
    That looks like the other side is not sending traffic. Hence my questions about what is on the other side and what the makeup of the phase 2s is. No idea what could be wrong. I would be guessing. Show everything.
  • IPSEC between PFSense 2.3.1 and Zyxel USG 1100 Router

    1
    0 Votes
    1 Posts
    693 Views
    No one has replied
  • Configuration IPSec on version 2.3.2

    1
    0 Votes
    1 Posts
    940 Views
    No one has replied
  • IPSEC will connect with PSK+XAUTH, instead of PSK

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • 0 Votes
    14 Posts
    5k Views
    H
    This problem still exists. Pls help me.
  • How change maximum concurrent l2tp client

    1
    0 Votes
    1 Posts
    576 Views
    No one has replied
  • VPN IPsec GRE: Cisco <-> pfSense

    7
    0 Votes
    7 Posts
    2k Views
    N
    In order to get the spare public IP on the pfsense box I am thinking of moving the outside interface into a l2 vlan. However my cisco ASA is doing the PPoE to the ISP I am sensing that the routing from this secondardy link isnt going to work. I could maybe use the pfsense box to do the PPoE couldnt I?
  • S2S pfS <-> USG 20 - Initiation only works from USG20

    1
    0 Votes
    1 Posts
    490 Views
    No one has replied
  • VPN IPsec GRE: Cisco <-> pfSense

    4
    0 Votes
    4 Posts
    2k Views
    J
    Indeed. But this post is not in direct line with my initial issue as the remote IP is not my router https://forum.pfsense.org/Smileys/default/wink.gif
  • Multiple Phase2 Issues

    2
    0 Votes
    2 Posts
    2k Views
    DerelictD
    Setting IKE SA, IKE Child SA, and Configuration Backend from Control to Diag in VPN > IPsec, Advanced should give you more information in those logs.
  • Known issues with L2TP/IPSEC PSK on pfSense v2.2.x ????

    10
    0 Votes
    10 Posts
    2k Views
    M
    @AxSD: I followed this guide too but it does not seem to work for OS X: https://doc.pfsense.org/index.php/L2TP/IPsec So if I did not buy a pre-built unit from you guys, how can I mimic this exporter feature? it works fine with OS X and macOS. just make sure that you configure the floating rule mentioned at the bottom (troubleshooting)!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.