• OpenVPN to IPSec?

    6
    0 Votes
    6 Posts
    3k Views
    M
    I finally got around to this and it's working great. Thank you. If I wanted to route all internet traffic through the site-to-site VPN, is this article still valid? https://doc.pfsense.org/index.php/Routing_internet_traffic_through_a_site-to-site_IPsec_tunnel#Configure_outbound_NAT At the end, it says to modify the Outbound NAT at Site B (where you want your Internet traffic to exit), even though you want Site A to use the Internet at Site B. Is that still correct? Edit: This worked perfectly, I missed where it said to add a route of 0.0.0.0/0 at Site A, thus my confusion.
  • Please compile strongswan using the –dhcpplugin

    1
    0 Votes
    1 Posts
    624 Views
    No one has replied
  • Mikrotik to pfsense VPN. Can get phase 2 to link up

    4
    0 Votes
    4 Posts
    1k Views
    G
    pfSense defaults work fine, considering you replicated the settings correctly on RouterOS.
  • 0 Votes
    2 Posts
    2k Views
    jimpJ
    Turn up the logging on both sides as detailed here: https://doc.pfsense.org/index.php/IPsec_Troubleshooting#Common_Errors_.28strongSwan.2C_pfSense_.3E.3D_2.2.x.29 Usually that would mean either there is a mismatch or it's not matching the connection properly (remote gateway and identifier are not matching)
  • IPSEC Mobile Clients with IPv4 / IPv6 connection

    3
    0 Votes
    3 Posts
    1k Views
    L
    Hm, at least Strongswan should be able to do what we need : https://www.strongswan.org/testing/testresults/ipv6/net2net-ip4-in-ip6-ikev2/ So it is not possible with the GUI settings or is it prevented by some other conflict? Any idea? Thanks Andreas
  • 0 Votes
    3 Posts
    1k Views
    G
    You can do this with gateway groups and dynamic DNS, but it is not very reliable. The best way to do it is to set up GRE tunnels over IPsec transport mode, with OSPF on top of it to handle the routing.
  • IpSec Ikev2 Tunnel Up, but not passing internet traffic

    9
    0 Votes
    9 Posts
    3k Views
    J
    Hi daxpfacc, thank you for that hint. I just added both the OpenVPN and IPsec Subnets and allowed queries, but it still does not work. Kind regards, Jannik
  • Route traffic between IPSEC vpns

    5
    0 Votes
    5 Posts
    2k Views
    J
    Glad to have helped
  • IPSec Failover with BIN/NAT

    1
    0 Votes
    1 Posts
    721 Views
    No one has replied
  • IPSec Between iOS 9 and PFSense 2.3: Working Configuration

    5
    0 Votes
    5 Posts
    9k Views
    E
    Yes but the type of encryption can easily be tested after configuration in general and otherwise the article is up to date (and still working). But yes the article could be upgraded in respect of encryption.
  • IKEv2 with EAP-RADIUS: Any fallback option if the RADIUS server is down?

    1
    0 Votes
    1 Posts
    741 Views
    No one has replied
  • Pfsense <->pfsense, VPN established, no traffic -> suddenly traffic

    2
    0 Votes
    2 Posts
    983 Views
    F
    I guess I got it -> it was a problem with the package HA-proxy. After uninstalling it, I don't have those effects.
  • Phase 1 Proposal algorythms (2.3) => Why only 1 proposal ?

    3
    0 Votes
    3 Posts
    759 Views
    V
    Thanks.
  • Migrate from 2.15 to 2.3 - FTP problem via IPSEC

    3
    0 Votes
    3 Posts
    784 Views
    P
    The FTP is already in passive mode. But before the migration, they have any problem to transfer files with FTP via IPSEC and i am wondering where is the issue and if a new thing is here with this new version.
  • Reachable network dependant on Phase 2 ordering

    4
    0 Votes
    4 Posts
    1k Views
    C
    The raw output of 'ipsec statusall' would be helpful.
  • Draytek to pfsense route all traffic

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Minor interface glitch 2.3

    3
    0 Votes
    3 Posts
    859 Views
    J
    Thank you!
  • Getting IPSec Working with 2.2.6 & iOS 9

    2
    0 Votes
    2 Posts
    1k Views
    R
    OK, so if I specify a Group Name in iOS, the request becomes aggressive.  It still fails at: May 10 12:06:15 charon: 06[IKE] <15> found 1 matching config, but none allows XAuthInitPSK authentication using Aggressive Mode May 10 12:06:15 charon: 06[CFG] <15> looking for XAuthInitPSK peer configs matching 192.168.XX.XXX…70.196.XXX.XXX[VPN] From VPN: IPsec: Edit Phase 1: Mobile Client - Phase 1 Proposal: Authentication method - Mutual PSK & Xauth Negotiation mode - Aggressive My Identifier - My IP Address Peer Identifier - Distinguished Name - VPN Pre-Shared Key - XXX What am I missing?
  • IPSec VPN drops randomly and never reconnects

    3
    0 Votes
    3 Posts
    4k Views
    J
    I think I figured it out…..very stupid, of course. It seems that if I ping the remote LAN subnet, the tunnel will come back up by itself. I suppose I could set the auto ping IP to the remote LAN IP and that should keep it up. I unfortunately don't have control over the other end (and the admin's that do are very incompetent) so I can't change to IKEv2 on the remote end. Would enabling 'Make before Break' have any effect?
  • Disable or enable Phase 1 from command line

    4
    0 Votes
    4 Posts
    3k Views
    V
    Were you able to find a command to enable/disable IPsec tunnels from the CLI? I would also like to know if there is a way to do this, because I would like to implement an IPsec multi-WAN failover.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.