• Sonicwall IKEv2 Payload processing errors

    7
    0 Votes
    7 Posts
    9k Views
    M
    @ctyokley I’ve seen something like that happen. Phase 2 pfs negotiations succeed until it’s time to rekey. But not ok pfsense. Probably thinking of an ASA maybe
  • IPsec one client connects, other does not

    3
    3
    0 Votes
    3 Posts
    569 Views
    A
    @Konstanti Thanks! I will take a look at this. The problem is that I don't know for sure that this is the problem. I would hate to go through regeneration and deployment of new certificates and STILL have the issue. I've managed to get everything (HTTPS/IPsec) working, except for the iPad. I'm guessing that the fragmentation is the issue since it's the last thing I see before destroying the connection. It's not urgent that I get this working on the iPad since I do have a working IPsec on my phone. It would be rare I'm travelling with the iPad and NOT also have my phone available.
  • site to site loosing html trafic

    2
    0 Votes
    2 Posts
    390 Views
    F
    after much searching and trial and some error. I think i have solved the problem. It seemed to be loosing or having packets getting corrupted or out of order as i have seen some documents describe it. I ended up changing the maximum MSS on one firewall. Since i am new at this, it took a long time to find this setting so i will include it here for others that may be having similar problems. system, advanced. firewall & nat tab Scroll down to VPN packet processing, check box enable MSS clamping on VPN traffic. Maximum MSS 1400. I disconnected the VPN and let it reconnect, just to make sure changes happened. After that print jobs between builds and web pages worked again. Thanks.
  • Remote server unreachable over Site-to-Site VPN

    4
    0 Votes
    4 Posts
    632 Views
    V
    @Tirthankar You need to allow access from the remote site here, so from 192.168.1.0/24.
  • IPSec Phase 1: Allow connections from any IPv4 and any IPv6 (Dual Stack)

    2
    0 Votes
    2 Posts
    400 Views
    L
    Nothing to discuss here I guess. Ticket has been opened in Redmine and a todo was assigned to version 2.8.0.
  • Help with Samsung S22 ipsec mobile client VPN to pfSense

    5
    0 Votes
    5 Posts
    817 Views
    A
    I carefully reviewed my settings against a working configuration and discovered that a few things were misconfigured or missing. I now have it working! Now to try the same on an iPod!
  • IPsec traffic Forward

    1
    0 Votes
    1 Posts
    301 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    3 Views
    No one has replied
  • IPsec trouble disconnection between PFsense and FortiGate

    6
    0 Votes
    6 Posts
    2k Views
    planedropP
    Yeah like @michmoor is mentioning, I'd double check the config on both sides for Phase 1 and 2 and be sure they are identical. If that still doesn't work then I'd dig deeper on the deleting SA issue mentioned by @Konstanti Might also be worth checking to be sure the Fortigate is fully updated so there isn't a chance for some old bug.
  • Support for Post-quantum Preshared Keys and/or Multiple Key Exchanges

    1
    1 Votes
    1 Posts
    286 Views
    No one has replied
  • IPSEC PfSense 2.7.2 between PA-VM

    1
    0 Votes
    1 Posts
    186 Views
    No one has replied
  • Risks To Enabling MSS Clamping on IPSec?

    1
    0 Votes
    1 Posts
    456 Views
    No one has replied
  • IPSEC sending connection to wrong NAT IP

    2
    3
    0 Votes
    2 Posts
    444 Views
    L
    Tried to create a 1:1 NAT, but still not working
  • Admin access via ipsec

    4
    0 Votes
    4 Posts
    656 Views
    F
    @mcury It was a missing firewall rule - now working fine.
  • Traffic Graph won't show the IPs local and remote.

    1
    1
    0 Votes
    1 Posts
    262 Views
    No one has replied
  • IPSec VTI not working

    1
    0 Votes
    1 Posts
    359 Views
    No one has replied
  • configuring NAT for IPSec (each site is exactly the same..)

    4
    0 Votes
    4 Posts
    667 Views
    V
    @ethan-103 You can do this with BINAT for sure, but this requires a policy-based tunnel. With VTI you can configure a NAT 1:1 to achieve this. For example 10.0.20.0/24 would nat to site A 172.16.5.0/24 ( 10.0.20.100 = 172.16.5.100) For this example you have to add a NAT 1:1 rule to the VTI interface at A, where the "External subnet IP" is 10.0.20.0 and the "Internal IP" is type Network > 172.16.5.0/24.
  • 0 Votes
    3 Posts
    941 Views
    C
    Update: Wifi calling seems to work with no outbound nat rules other than the default enabled, however I can only get it to actually use it when I put the phone in a faraday cage that blocks cell, or airplane mode. I don't know if this is something specific with my carrier, or my Pixel 8 pro software. I did test with and s21 and it didn't use it until I did the airplane mode and enable wifi thing. Not sure if it is preferring LTE instead of wifi because of how strong our LTE is in our area, or if this is a cause of a misconfigured fire wall. Still having a bit of a head scratcher at this one, especially because I went into settings and told it to prefer wifi over LTE, but who knows.
  • macOS 14.2 - Can’t Connect With Saved Pre Shared Key

    1
    0 Votes
    1 Posts
    341 Views
    No one has replied
  • How to configure an IPsec VPN failover with 2 gateways on each end

    1
    0 Votes
    1 Posts
    253 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.