• 0 Votes
    5 Posts
    1k Views
    M
    Have you enabled the CISCO unity feature? - I think Chris had made a comment about this already. You don't see this traffic when you do a packet capture on your interfaces directly from pfsense?
  • OSPF and Static Rouge

    1
    0 Votes
    1 Posts
    728 Views
    No one has replied
  • IPSec with pfsense 2.3 & Greenbow didn`t work

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • FTP via ipsec working one way but not the other

    2
    0 Votes
    2 Posts
    954 Views
    M
    Haven't yet worked this out… Any ideas why the reply to the initial FTP request has a source IP of the physical IP on my WAN Interface?  To the internet, the ISP NATs this to a global IP, but this isn't relevant I believe State of this reply: WAN -- tcp -- <wan ip="">:42390 --> <remote ftp="" server="" ip="" across="" vpn="">:21 -- SYN_SENT:CLOSED</remote></wan>
  • Traffic not routed to IPSec but default gateway in stead

    3
    0 Votes
    3 Posts
    1k Views
    G
    @cmb: That doesn't match the P2 you have defined, so it's not supposed to go over the VPN. Needs to be source of the network, not single IP, like your other one. I'm not quite sure what you mean. The given configuration is mandatory by the provider of the tunnel endpoint… It works using the same config on another router like a Draytek!
  • Dead peer detection required on both ends?

    3
    0 Votes
    3 Posts
    2k Views
    S
    well and i dont know for exactly sure they are ALIX, but they are older red netgate units with 3 interfaces.  but they do keep repeatedly dropping their ipsec tunnels every day, and i constantly have to log into them and restart the tunnels. i did have 2 even older and smaller silver netgate's whcih both did not survive the 2.3.x upgrade.  one died and woudlnt reboot, one repeatedly said corrupt update file.  replace them both with brand new units. the rest of the history on this project is, previous consultancy deployed all these netgate units and used openvpn back to HQ (and never updated them).  old consultants were out out and i was in, their HQ moved to a new location/IP, so all these firewalls were left on their on for a few months (no VPN). when i finally get around to them and update them to 2.3.x and build IPsec tunnels back to HQ, now the tunnels (and often the internet as well) keep going up and down.  as the customer does not have any technical people working for them full time, all they see if firewalls that dont stay up after i upgraded/VPN'd them all. so right now im grasping at straws trying to figure out whats wrong.  i have SO many other pfsense installs out in the field (all newer PCs or newer pfsense hardware) and these dinosaurs are the only ones giving me troubles.  but there are about 50% of the netgates that fall into the same age group that are working 100% fine.
  • [SOLVED] 2.3.1 IPSec Mobile Client Failure

    10
    0 Votes
    10 Posts
    3k Views
    M
    A clean install with 2.3.1 and a quick setup of the ipsec site-to-site, came up straight away. I played with the IKE settings between Auto, v2 and v1 - As cmb said,  my config must have been different when I was comparing. Thanks…
  • IPSec - Upgrade to 2.3 removes AES-GCM encryption options from Phase 1

    8
    0 Votes
    8 Posts
    4k Views
    jimpJ
    Also, FYI- If you choose to use AES-GCM in P1 for an IKEv2 tunnel, use AES-XCBC for the "hash" algorithm (really it's a PRF in that case and not a hash…).
  • IPsec connection established, no traffic

    4
    0 Votes
    4 Posts
    1k Views
    X
    Ok, with the help of some experts we got it working. If you ipsec gives you a local network that is not your local network create a virtual ip that is that subnet. Then add a secondary ip in that network on your local computer. Add a static route on the computer. And it's up.  ;D
  • IPSEC VPN on single interface?

    2
    0 Votes
    2 Posts
    3k Views
    C
    You can't do LAN and WAN with one interface like that, but you can do what you're describing with only WAN, no need for two interfaces.
  • IPSEC Net2Net Aggressive not working after reboot

    2
    0 Votes
    2 Posts
    734 Views
    jimpJ
    Probably because it's getting a state leaving WAN before the VPN is up. Waiting allows the state to clear. Add a floating rule to REJECT outbound on WAN for any destination matching your remote VPN subnet(s). That will stop the leakage.
  • IPSEC is UP but no internet

    3
    0 Votes
    3 Posts
    891 Views
    J
    @kapara: what about under IPSEC status?  Do you have any Child SA's? or is only P1 connected? Thank you for your answer. IPSEC Status is fine and services ir running fine . No child SAS. Yes only one P1 connected right now Thank you
  • IPSec for Mobile Clients not working 2.3_1

    22
    0 Votes
    22 Posts
    6k Views
    K
    ok thanks.  I am struggling to find a clear tutorial for this on 2.3.
  • More IPSEC woes…. Horrible performance

    6
    0 Votes
    6 Posts
    1k Views
    K
    I am going to try changing the MTU to 1400 tonight. What is interesting is when I switched to 3des/sha1 from AES on the APU I was able to pass 3-4 mbit on windows file transfers compared to maximum 1.5 on AES 128/Sha1
  • [SOVLED] How to restart ipsec service from command line

    19
    0 Votes
    19 Posts
    37k Views
    K
    With the new version 2.3 are we able to take advantage of all the strongswan commands? I am running 2.2.6 and I lost all connectivity to the GUI during setup of a VPN.  Since I cannot reboot (Business Hours) I wanted to check the status of the VPN's and I was able to run from shell:  ipsec status and was able to get details on all configured tunnels. https://wiki.strongswan.org/projects/strongswan/wiki/IpsecCommand Can we use this to restart the ipsec or is that not recommended?
  • IPSEC EAP-MSCHAPv2Firewall Rules

    3
    0 Votes
    3 Posts
    898 Views
    N
    @cmb: That's handled automatically. Well that is good but for those that come from other firewall system, it is really an abnormally.  I would be better for the system assigned rules to be shown grayed out or even in a different color and not editable.  Thanks.
  • IPSEC VPN with Draytek Router

    3
    0 Votes
    3 Posts
    3k Views
    U
    I think i have found the issue. Default in IPSEC / Advanced Settings the option Configure Unique IDs as is set to yes changed this to no and restarted the VPN and now traffic is working again. previously with Configure Unique IDs as set to yes the only way to get traffic flowing again would be to reboot the PFsense box.
  • Major performance issues ipsec 2.1.5 to 2.3.1 Help if possible????

    6
    0 Votes
    6 Posts
    3k Views
    K
    I just updateted my NTP settings.  Disable time sync in the VM (pfsense 2.3) and rebooted
  • [Solved/Patch] pfSense (dest) -> FritzBox -> Internet <- FritzBox (src)

    2
    0 Votes
    2 Posts
    1k Views
    H
    little update… did some modifications /etc/inc/vpn.inc 1042 if (count($rightsourceips)) { 1043 $rightsourceip = "\trightsourceip = " . implode(',', $rightsourceips) . "\n"; 1044 } 1045 } + + if (isset($ph1ent['avmvirtualip'])) { + $rightsourceip = "\trightsourceip = {$ph1ent['avmvirtualip']}\n"; + } 1046  1047 if (!empty($ph1ent['caref'])) { 1048 $ca = lookup_ca($ph1ent['caref']); 1049 if ($ca) { /conf/config.xml (somewhere in phase1) <avmvirtualip>123.123.123.123</avmvirtualip> (of course, "avmvirtualip" can be replaced with anything) I think, this should be an input field in phase 1 of IPsec. Something like "Force virtualip for remote"… If devs agree, I could write a little patch to include it. Perhaps an advanced text input for more individual configs? For me, this just needs to work the next 2 weeks. But it might be helpful to others?
  • IKEv2 Mobile with Windows 7 (No Route)

    3
    0 Votes
    3 Posts
    2k Views
    K
    Time to upgrade all users to Windows 10 :-)  works great on there with the powershell command!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.