• StrongSwan IKEv2 EAP-TLS VPN to Android

    1
    0 Votes
    1 Posts
    4k Views
    No one has replied
  • Pfsense 2.1.5, when phase 1 drops, phase 2 does NOT

    1
    0 Votes
    1 Posts
    633 Views
    No one has replied
  • IPSec between version 2.1.2 and version 2.2.5

    6
    0 Votes
    6 Posts
    2k Views
    W

    FIXED:

    Thanks for the replies.

    I can confirm that the reason was due to the fact that our key had a space character at the end.

    This page is very helpful: https://doc.pfsense.org/index.php/IPsec_Troubleshooting

  • 0 Votes
    19 Posts
    6k Views
    B

    I know how automatic rules turn into manual ones. My question is what created the automatic rules in the first place (IOW, what's their root cause?), in particular since they only appeared at one site, without a difference between the sites that could explain them (to me).

  • Help with IPSEC not connecting

    12
    0 Votes
    12 Posts
    8k Views
    D

    Yeah I've double checked all of that, the client doesn't want to upgrade yet because he is afraid of it causing issues.  But i think that may be the only choice

  • PfSense 2.2.5 <-> Server 2008 R2 RRAS

    1
    0 Votes
    1 Posts
    995 Views
    No one has replied
  • Shrewsoft Mobile IPSec Client Acting Up

    6
    0 Votes
    6 Posts
    1k Views
    D

    @jimp:

    I don't have the link handy but someone else here on the forum posted that they were able to get the powershell command to work to allow for split tunneling. That may have been on Windows 8, though, I'm not sure if it also works on 7. It's worth a shot though.

    The powershell commands are only for windows 8/10. No luck on 7. It seems the only way this can work with windows 7 is.

    Route all traffic over tunnel (Use Default Gateway on Remote Network selected on windows 7 client) Add Routes manually when connected to VPN Client
  • IPSEC Site-to-Site show me connected but I can't access

    7
    0 Votes
    7 Posts
    1k Views
    R

    So in my case doesn't show me any relevant information :(

  • IKEv2 MSCHAPv2 and Windows 10 client - not traffic goes through

    4
    0 Votes
    4 Posts
    5k Views
    P

    And importantly…add firewall rules...

  • IPsec with OS X 10.10.5 and PFSense 2.2.5

    5
    0 Votes
    5 Posts
    2k Views
    P

    I use Shrewsoft on 10.11.1 because I also use Windows 10 which allowed me to standardized my firewall settings and clients configurations for both platform.  Here's 10.11.1 I used as late as 12/02/2015 - http://nubisnovem.com/el-capitan-solution-mac-os-x-10-11-and-shrew-soft-vpn-client/

    I added my configurations for Firewall and Client via screenshots here - https://forum.pfsense.org/index.php?topic=102825.0  - this works and is used for both Windows 7-10 and latest MAC OS X

  • Ipsec not comming up

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • L2TP over IPSec

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ

    That's a known issue with L2TP/IPsec on Windows Clients. See the warning here: https://doc.pfsense.org/index.php/L2TP/IPsec

    I've move on to IKEv2, L2TP/IPsec is not a good choice these days.

  • Only two IPSec Phase 1 tunnel authentication methods available?

    2
    0 Votes
    2 Posts
    744 Views
    C

    Guessing that's not your mobile P1 you're looking at. The others are only applicable and configurable for mobile.

  • Second Phase 1 doesn't start on boot

    2
    0 Votes
    2 Posts
    677 Views
    C

    You remove the input validation to get that to work? There are reasons that config isn't permitted by the GUI. It should come up fine when traffic triggers it though.

  • Received INVALID_ID_INFORMATION error notify

    2
    0 Votes
    2 Posts
    10k Views
    C

    Split this to its own topic as it's not at all related to the thread you posted in.

    "received INVALID_ID_INFORMATION error notify" means your identifiers don't match. They wouldn't have before the upgrade either, racoon just (wrongly, really) didn't care. Info here:
    https://doc.pfsense.org/index.php/UpgradeGuide#Stricter_Phase_1_Identifier_Validation

    If you're using non-IP identifiers, you'll need to switch back to aggressive mode, and fix the P1s on both sides so the identifiers match.

  • Routing between two remote Ipsec Tunnel

    2
    0 Votes
    2 Posts
    953 Views
    N

    By chance it is possible to use an OpenVPN tunnel between site A and Site B, and after create a Pfsense rule to send packet from site A to site C?
    thank you

  • IKEv2 Android Roadwarrior Routing Issue

    2
    0 Votes
    2 Posts
    897 Views
    R

    Got it fixed. Ive put the local nets Ingo the routing section, seperated by space and everything works now AS it should. Not sure if all traffic is Router through the ipsec Tunnel, but that isnt important for me.

  • Web Config hangs with mobile client ipsec

    4
    0 Votes
    4 Posts
    912 Views
    S

    Just to follow up again this Error seems to hit the main dashboard page if the IPSEC Widget is enabled and also affects the Statis->IPSEC page.

  • IPSec lan-to-lan with PfSense and MikroTik - Not working!!!

    4
    0 Votes
    4 Posts
    3k Views
    M

    Hi,

    i know that mikrotik + pfsense  is working.

    Is phase1 ok ? –>yes go to phase2
    is phase2 ok ?

    From mikrotic forum:
    When you want to make a direct IPsec tunnel between MikroTik routers you must make sure that you have an exception rule in your NAT table for traffic from the local to the remote network which says "accept" (before your general rule that says "masquerade" or "src-nat").
    When you do not do that, the router will mistakenly NAT the traffic before it puts it into the tunnel, and no communication will be possible.

    I used on phase 1
    Encryption algorithm AES 256
    Hash algorithm

    |
    SHA1
    DH key group 2(1024)
    Lifetime 86400

    phase2
    Protocol ESP
    Encryption algorithms AES (auto)
    Hash algorithms SHA1
    PFS key group 2(1024)
    Lifetime 1800

    With other setting i ran in trouble.

    regards
    max |

  • Pfsense 2.1.5 tunnel wth srx100

    1
    0 Votes
    1 Posts
    636 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.