• IPSEC VPN

    3
    0 Votes
    3 Posts
    1k Views
    A
    That won't work.  I need to be able to set up pfsense as a client but using the ipsec instead of openvpn settings.
  • IPSec Security

    4
    0 Votes
    4 Posts
    1k Views
    L
    PFS keygroup 2 (1024bit) is rumored to be possible to break with NSA like budget. The PFS keygroup 5 should be fine as of now, higher PFS groups get really slow. For the symetric ciphers like 3DES and AES128 there is no real world break known, but as AES128 should be faster than 3DES you should use AES. The hash does not matter as it is used for integrity check to my knowledge, at least if you are not using preshared key which you should not do. Regards Andreas
  • IPsec failure after upgrade to 2.3 - resolved

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • PfSense as an IPSec / L2TP client

    3
    0 Votes
    3 Posts
    2k Views
    J
    No, unfortunately. Bought an ERLite-3 instead, lived with ~250 Mbps for a bit, and then decided that VPN is not worth all this trouble.
  • Any IPSec Mobile client that actually works in Windows?

    15
    0 Votes
    15 Posts
    4k Views
    M
    Hi ! Have you solved it ? Reading your post I remembered I had problems with ShrewSoft client. What fixed it for me was the setting NAT Traversal: Force  ( in mobile clients / advanced ) LP, Miro
  • IKEv2 Mobile clients and mapped drives

    1
    0 Votes
    1 Posts
    760 Views
    No one has replied
  • Does pfsense 2.3 supoort ipsec's high availability?

    1
    0 Votes
    1 Posts
    588 Views
    No one has replied
  • 1GB fiver link over IPSec

    10
    0 Votes
    10 Posts
    2k Views
    J
    Never mind I am blind haha ;D
  • Losing connection in ipsec phase 2 after 24 hours

    5
    0 Votes
    5 Posts
    3k Views
    T
    This issue has not reappeared in the last few days, and it used to occur at least once a day. The only major change to my configurations is to improve the stability of the PPPoE link to the Internet. I was using a USB Ethernet adapter for my PPPoE link and the link was quite unstable, typical PPPoE uptimes were a few hours max. I have since changed to a VLAN based solution to get my PPPoE traffic out of the pfsense environment. The result of this is that the PPPoE is now significantly more stable and at the same time the IPsec phase1 without phase 2 problem appears to have gone away. As well as being more stable the time to reconnect when the PPPoE link does fail has increased. With the USB Ethernet adapter the PPPoE Daemon would receive a TERM signal, shutdown, and then immediately reconnect. Now all the PPPoE outages look more like ISP issues and are loss of LCP echo, followed by a few attempts to reconnect. So the PPPoE link is down for a much longer time and does not instantly reconnect. So at this stage it looks like the IPsec loss of phase 2 may relate to the manner/frequency of link failure on the Internet link. I have left the IPsec links in IKEv1 and if the issue occurs again then I will hopefully be able to supply the appropriate logging information. Tim
  • 2.2.6-RELEASE IPSec & AWS VPN daily disconnects, multiple Phase-2

    2
    0 Votes
    2 Posts
    1k Views
    H
    How many phase 2 entries do you have? Make sure you're not running into https://forum.pfsense.org/index.php?topic=106260.msg592087#msg592087. Cheerio, Harry.
  • Ipsec error

    4
    0 Votes
    4 Posts
    4k Views
    M
    another error have been able to login with shrew vpn client soft but now no more access. error showing when login is negotiation timout occurred i have uninstall and reinstall still the same error. kindly help.
  • *FIXED* IPSec site-to-site transport mode GRE verification

    1
    0 Votes
    1 Posts
    978 Views
    No one has replied
  • After upgrading to 2.2.2\. IPsec not working.

    5
    0 Votes
    5 Posts
    9k Views
    L
    I had the same problem when upgrading from 2.1.5 to 2.2.6(chnging hardware and restoring the config etc.), in the end i needed to re-specify what interface the local endpoint of the phase1 entry, seems to have reset itself to the interface and not the virtual IP that was originally used. Hope this helps someone else.
  • User passwords for l2tp/ipsec

    1
    0 Votes
    1 Posts
    691 Views
    No one has replied
  • 2.3 L2TP/IPsec no l2tp interface

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    Read the warning note at the top of the wiki doc you linked – that won't work for Windows, for the exact case you have encountered.
  • IPSEC using VIP Alias (PPPoE) - PFSense 2.1

    2
    0 Votes
    2 Posts
    1k Views
    Z
    The only way I got it to work was to: Set up one pfSense gateway to connect to the internet via pppoe set up another pfSense as an IPSEC initiator and set up the IPSEC connection. Box (1) is my default gateway to the internet I route all traffic from (2) to (1) so that IPSEC box can route outwards to establish the IPSEC connection I set up a customer route from (1) to (2) for any traffic going to the remote site. PM me if you want more details.
  • IPSec and NAT

    2
    0 Votes
    2 Posts
    1k Views
    C
    That's the nature of how it works. Traffic matching the SPD is intercepted and sent across the IPsec if there is a matching SA. If the IPsec can't come up, it gets dropped. IPsec transport mode with a gif or GRE tunnel and a dynamic routing protocol is how failover is accomplished. Or policy routing though that's usually more complicated since you have to make sure routing on both ends is updated appropriately.
  • Any way to connect a Mac as mobile IPsec client?

    5
    0 Votes
    5 Posts
    4k Views
    -flo- 0-
    Yes, this page is a valuable resource also for other scenarios. It was the first reliable source I came across stating that the built in client from OS X should be working in this setup at all.
  • Pre Shared key for Site To Site and Mobile VPN

    1
    0 Votes
    1 Posts
    722 Views
    No one has replied
  • Site to site IPSec, pfSense 2.2.5 with IPCop 2.1.9

    1
    0 Votes
    1 Posts
    646 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.