• Problem with internal LAN user to make VPN connection

    1
    0 Votes
    1 Posts
    420 Views
    No one has replied
  • How to install FARP plugin for Strongswan?

    3
    0 Votes
    3 Posts
    2k Views
    S

    thanks for the rapid response!

  • Found bug in ipsec xauth ("§" character in password)

    3
    0 Votes
    3 Posts
    610 Views
    ?

    Hi  jimp,

    thx for your utf8 tip. We use LDAP and with activating "UTF8 Encode" it works flawless.

  • VPN CONFIGURATION.

    1
    0 Votes
    1 Posts
    627 Views
    No one has replied
  • Create IPSEC via script

    2
    0 Votes
    2 Posts
    488 Views
    jimpJ

    Not with any existing script.

  • Multiple Phase 2's network crosstalk

    1
    0 Votes
    1 Posts
    642 Views
    No one has replied
  • Tunnel all/specific subnets fails after upgrade to 2.2.4

    1
    0 Votes
    1 Posts
    582 Views
    No one has replied
  • Gre tunnel with Ipsec file transfer

    1
    0 Votes
    1 Posts
    740 Views
    No one has replied
  • Missing options when adding new ipsec tunnel

    1
    0 Votes
    1 Posts
    607 Views
    No one has replied
  • IPSec/L2TP on 2.2.4 - IPSec OK, no traffic to L2TP

    3
    0 Votes
    3 Posts
    1k Views
    R

    I have exactly the same problem. And no solution.

  • IKEv2 / transport is not working in 2.2.4

    1
    0 Votes
    1 Posts
    795 Views
    No one has replied
  • Missing support for ECDSA certs

    1
    0 Votes
    1 Posts
    743 Views
    No one has replied
  • Ipsec+crl

    1
    0 Votes
    1 Posts
    849 Views
    No one has replied
  • DNS Problem with iPhone after Upgrade to 2.2.4

    1
    0 Votes
    1 Posts
    448 Views
    No one has replied
  • Upgrade from 2.2.1 to 2.2.4 broke IPsec VPN

    1
    0 Votes
    1 Posts
    797 Views
    No one has replied
  • MOVED: VPN through squid proxy not connecting

    Locked
    1
    0 Votes
    1 Posts
    409 Views
    No one has replied
  • Ipsec can't stop / won't stop, and many SAs won't connect

    1
    0 Votes
    1 Posts
    684 Views
    No one has replied
  • VPN Tunnel with Cisco UC560\. Tunnel is UP but no traffic…

    1
    0 Votes
    1 Posts
    730 Views
    No one has replied
  • IPSec Issues 2.2.3 and 2.2.4

    32
    0 Votes
    32 Posts
    6k Views
    R

    Not and ISP issue, same hardware on two different providers behaves the same, also on the same provider. Different hardware on the same two different providers work without issue, also on the same provider.

    Quality of circuits is outstanding in all my remote locations. I'm using a hub spoke model, with a pair of Palo Alto 3000 series as the hub. Multiple spokes, all pfSense. Any pfsense running 2.2.2 has no issues (AES-256). All running 2.2.4 work fine except the pfsense official hardware firewall from the store.

    I have no issues other than with this one firewall hardware. All other factors I can remove, have been removed.

    CMB has I think all the details he's asked for, but I'm sure if he needs more he'll ask.

    And trust that I have nothing but respect for CMB and the team at ESF. I honestly believe that pfsense is the best platform for perimeter security out there, commercial or not. The only reason I use PAN as my hub is because of executive concerns around an open source platform doing all security between all subnets, local and remote.

    I'm just in an awkward position. I promised the CEO of the company that I would get him the best of the best, rather than what I usually build using spare parts, and I looked like an amateur after 2.2.2. All the technical reasons aside, he sees me handing him a black box that doesn't work as I told him it would. Meanwhile an old grinder under the desk supports 10-20 people on a regular basis and never blips.

    The only reason I bought the pfsense branded hardware was because I read these forums regularly, and I see pfsense experts brag all the time about their bulletproof hardware from the pfsense store. I wanted to be one of those too because quite frankly although I have good good success with old hardware, one day I'm sure that might end (given the end user problems on these forums). :)

    I'm grateful, honest!

    Cheers,

  • StrongSwan Client Linux no password dialog EAP-MSCHAPv2 [SOLVED]

    2
    0 Votes
    2 Posts
    3k Views
    M

    Hi

    Please see here: https://wiki.strongswan.org/issues/1062. It actually might work with the shipping 5.1.x binaries but I was already down the rabbit hole. Try this: Edit the /etc/NetworkManager/VPN/nm-strongswan-service.name file and under [GNOME] add "supports-external-ui-mode=true" without quotes. Create your connection using Network Connections in the NetworkManager applet. Invoke the connection and the save password dialog should popup. Otherwise follow the directions in the link above to build the package from source.

    This is only affecting Debian distros like Ubuntu and Mint. I tried many things including some ln -s to various places. If this does not work for you post back and we can find out what links need to be made.

    /M

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.