• Monitor Road Warrior VPN (pptp,IPSec, OpenVPN) by SNMP

    1
    0 Votes
    1 Posts
    4k Views
    No one has replied
  • Upgraded to 2.2.3, IPSec broke on Windows

    5
    0 Votes
    5 Posts
    1k Views
    Z

    Actually, even after I downgraded it to 2.2.2, my Windows machine is still borking… I will reinstall Windows and test again.

  • IPSec Amazon VPC / IPSec Firewall / IPSec SSH (2.2.3)

    1
    0 Votes
    1 Posts
    620 Views
    No one has replied
  • IPsec stops working, Diagnostics Tables entry

    6
    0 Votes
    6 Posts
    2k Views
    A

    Hi
    Upgraded to Update-2.2.4-DEVELOPMENT-i386-20150704-0731
    IPsec works with this version, no configuration changes where required.
    Did not get time to test the MSS clamping, needed the network so the choice was go back to 2.1.5 or try 2.2.4 Development

    System is 32 bit
    TSO and LRO where not disabled

    The good news is that the problem in 2.2.3 seems to have been resolved in 2.2.4 Development

    Thanks
    markl

  • PfSense 2.2 as IPSec/L2TP client

    4
    0 Votes
    4 Posts
    1k Views
    S

    @jly2680:

    ipsec/ikev2mschapv2 bec l2tp has some l2 overheads and outdated.

    whut?  :o

  • SOLVED : site-to-site with multiple vlan issue

    7
    0 Votes
    7 Posts
    2k Views
    C

    just for a positive update : it started working by itself wothout any intervention.

    i've lost a part of the log (maybe log rotate process …) but look like ipsec reset on 4th july and then the faulty vlan work now over ipsec

    very very weir but solved now  :D

  • Pfsense connecting as IPsec client to a Cisco VPN concentrator?

    1
    0 Votes
    1 Posts
    802 Views
    No one has replied
  • Pfsense 2.2.3 IPSEC S2S VPN Monitoring

    2
  • IPsec connection to Cisco router

    2
    0 Votes
    2 Posts
    651 Views
    ?

    Please try out to use the "aggressive mode" on both sites!

  • Odd IPSec tunnel issue

    2
    0 Votes
    2 Posts
    662 Views
    C

    Guessing your wireless is on a different subnet? You need a matching P2 for that network.

  • 2.2.2 -> 2.2.3 Upgrade: KeyID Tag Broken?!

    4
    0 Votes
    4 Posts
    1k Views
    C

    This was fixed in 2.2.4 last week.

  • [2.2.3] High CPU usage when going to the IPSec status page - Lot of SAD

    1
    0 Votes
    1 Posts
    821 Views
    No one has replied
  • Route a WAN IP over the tunnel

    5
    0 Votes
    5 Posts
    1k Views
    M

    After disabling and enabling the phase 2 on one end, the tunnel came up.
    It was not possible to ping through the tunnel but it looks like the routing works.

    I then checked the ipsec firewall roules but they were ok (IPv4 * * * * * * none). I also added such rules on the lan interface on both ends.
    Still, the ip is not pingable.

    EDIT:
    After adding an outbound NAT rule and switching to hybrid mode, I can finally reach through the tunnel.
    Adding a third phase 2 shows the red arrow again on this phase 2. Re-enabling it does not help, even after a few times.
    The ipsec log shows the phase 2 as if it was connected:

    charon: 10[CFG] received stroke: add connection 'con1002' Jul 7 22:29:48 charon: 10[CFG] added child to existing configuration 'con1000' Jul 7 22:29:48 charon: 07[CFG] received stroke: route 'con1002' Jul 7 22:29:48 ipsec_starter[35735]: 'con1002' routed

    But the red arrow on the status page stays and the tunnel is not connected in fact.

  • IPSec Tunnel IKE2 to ASA does only the last SA; not all 4

    9
    0 Votes
    9 Posts
    3k Views
    A

    Still waiting for help; yes, it works fine under IKEv1; but need to have it working in IKEv2.  ;) Either with hack, or NATting 4 (was 2 before) local subnets 10.1.10.10/24,10.1.10.20/24,10.1.10.110.110/24, and 10.1.10.120 into 10.41.38.0/22, so we can only use 1 SA. Tried NAT 1:1 but that did not work.

    Any help appreciated.

  • IPsec between pfsense and ZyWall usg100-plus with certificates

    1
    0 Votes
    1 Posts
    646 Views
    No one has replied
  • Creating a rule for IPSEC VPN

    1
    0 Votes
    1 Posts
    649 Views
    No one has replied
  • New IPSEC Tunnel ISAKMP Rule Not Being Auto Created

    1
    0 Votes
    1 Posts
    804 Views
    No one has replied
  • Charon does not match sent identity to configured one

    5
    0 Votes
    5 Posts
    2k Views
    G

    @cmb:

    I'm going through all the possible combinations there now doing testing, with an automated test setup to iterate through all the possibilities. We'll have that resolved for 2.2.4.

    Awesome!  :D

  • Ipsec to asa 5545x drops every few minutes

    2
    0 Votes
    2 Posts
    600 Views
    R

    Can you post debugging logs of both sides?

  • Ipsec vpn using x.509

    2
    0 Votes
    2 Posts
    717 Views
    Z

    i have tried specifing the wan ip address as CN in the certificate …. no luck.
    can anyone share their experience on ipsec with rsa please?

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.