• Any way to connect a Mac as mobile IPsec client?

    5
    0 Votes
    5 Posts
    4k Views
    -flo- 0-

    Yes, this page is a valuable resource also for other scenarios. It was the first reliable source I came across stating that the built in client from OS X should be working in this setup at all.

  • Pre Shared key for Site To Site and Mobile VPN

    1
    0 Votes
    1 Posts
    682 Views
    No one has replied
  • Site to site IPSec, pfSense 2.2.5 with IPCop 2.1.9

    1
    0 Votes
    1 Posts
    595 Views
    No one has replied
  • Upgrade from 2.2.6 to 2.3 broke mobile IPSec [fixed]

    10
    0 Votes
    10 Posts
    3k Views
    J

    Thanks makes total sense. thanks for your help

  • Improvement proposal IPSec IKEv2 - USERS in user manager - save EAP key

    4
    0 Votes
    4 Posts
    1k Views
    jimpJ

    No, they are not encrypted on disk. They're in the clear because they have to be for EAP to work properly with strongSwan (I misspoke and said mpd earlier, not sure where that came from…)

    https://doc.pfsense.org/index.php/Why_are_some_passwords_stored_in_plaintext_in_config.xml

  • IPSec Site-to-Site VPN it is possible to create a Remote Gateway group?

    1
    0 Votes
    1 Posts
    914 Views
    No one has replied
  • 0 Votes
    2 Posts
    916 Views
    C

    You have to add a P2 with the NAT in that case, otherwise it never enters enc0 to be translated and sent across.

  • 0 Votes
    5 Posts
    2k Views
    J

    I have the same problem. Can you share which NAT settings did you changed? Thanks

  • Ipsec tunnel to windows server 2012 R2

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Configure VPN / IPSec with a routed public IP

    1
    0 Votes
    1 Posts
    572 Views
    No one has replied
  • IKEv2 with EAP-MSCHAPv2 connected but no internet access (Resolved)

    3
    0 Votes
    3 Posts
    5k Views
    R

    Had similiar problem (0.0.0.0 route always added) when creating VPN from Windows GUI and PowerShell helped. Thanks.

  • Port 4500 and 500 are blocked by pfsense?

    2
    0 Votes
    2 Posts
    778 Views
    C

    Maybe, depends on your config. By default they're both allowed outbound from LAN if that's what you mean.

  • IPSec Mobile Client not able to access Point-to-Point

    1
    0 Votes
    1 Posts
    565 Views
    No one has replied
  • Pfsense 2.3 DNS server issue

    3
    0 Votes
    3 Posts
    1k Views
    G

    Thank you for your help. Unfortunately I had to revert back to 2.2.2 because of this, as it's a production environment, but I will try again on the first occasion and let you know.

    Never realized that a plug in was required in the new version.

  • IPSec problem with pfSense 2.3 - DPD path probing fails

    3
    0 Votes
    3 Posts
    1k Views
    E

    -> cmb

    Thank you for your statement. You are absolutely right that it is not the "finest" solution that WAN and LAN are on the same subnet but they are segregated via VLAN and not bridged. The WAN uses a gateway that`s why it has a static ip. This gateway is used by another network with the same subnet which is not connected to the first network with the same subnet. This needs to be changed but the reason was a connection of two networks that were not planned intentionally and the change has not been done yet.

    In the "first" subnet with pfSense the IPSec clients are in the subnet 10.21.32.0/24, LAN is 10.21.30.0/24 (OpenVPN Clients in 10.21.31.0/24).

    I changed the subnet for WAN (10.21.29.0/24) for testing on the weekend but the problem remains.

    In the meantime I could figure out the problem. The problem only exists when MOBIKE is enabled (a new feature in 2.3 as far as I remember). If MOBIKE is disabled the DPD is sent via the WAN as intended. If MOBIKE is enabled the DPD is sent via LAN interface. So there could be a problem with the implementation of MOBIKE.

  • Script to reload automatically VPN

    4
    0 Votes
    4 Posts
    843 Views
    W

    You can use /usr/local/sbin/ipsec up con <number>Loop up the number in ipsec.conf.

    Use the command in cron(package)

    What device on the other side do you have problems with? I use this for connections to Fortigate devices, failing with phase2 rekeying.</number>

  • 0 Votes
    11 Posts
    3k Views
    DonnyD

    @Donny:

    Now IPSec Mobile work fine.
    1. I made a record FQDN my pfsene hostname: zwolle.xxxxx.com with Public WAN IP Address from my ISP in to the domain name system (DNS): xxxxx.com
    2. At local host computer windows 10, I tested PING to FQDN pfsene hostname > zwolle.xxxxx.com. it is worked.
    3. Create IPSec CA certificate, the common name whatever
    4. Create Sever Certificate to Common Name with FQDN pfsene hostname > zwolle.xxxxx.com. For Alternative name, I don't use Max OS, Linux and etc.
    5. Setup IPSec tunnel Phase 1 My identifier to Distinguished name with "zwolle.xxxxx.com" that is the same common name on Server Certificate.
    6. Another setup is the same pfsense document wiki
    7. export only IPSec CA to Windows 10 Client and then installation IPSec CA to Trusted Root Certificate Authorities.
    8. configuration the propertie of IPSec Connection adapter example at Security tab > IKEv2, Requir encryption and Secured password (EAP-MSCHAPv2) (encryption enable)
    9. test the connect by use username and password that created on Pre-SharedKeys tab
    10. finally connected and can ping to local host, copy files and etc.

    Donny

    Just want to be sure. the way i did it above, is it correct?

    Thank you. Donny

  • VPN Tunnel between pfSense 2.1 and Watchguard XTM 3 serie

    2
    0 Votes
    2 Posts
    993 Views
    D

    Hello,

    I have to configure vpn between pfsense and Watchguard M300, can you help me?
    Have you step-by-step guide?

    Thnaks!

  • IPhone to pfsense 2.3 not working

    8
    0 Votes
    8 Posts
    6k Views
    E

    Follow the instructions provided by kavara with IKEv2 via EAP-MSCHAPv2. IKEv2 is not only more secure than IKEv1 but much quicker in establishing a connection. Just send the certificate you downloaded from pfSense via E-Mail to your iPhone and click on it in the E-Mail to install, that`s all.

  • 0 Votes
    1 Posts
    791 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.