• Pfsense 2.1.5 -> 2.2.2

    2
    0 Votes
    2 Posts
    2k Views
    G

    Have you read the release notes on changes from 2.1 to 2.2?  Have you read other posts on this forum?  Some config examples might help.

    Anyway, check your phase 1 settings at both ends.  If NAT is involved at either end then that may have worked 2.1 to 2.1 but won't with 2.2, you will have to set the identifiers accordingly.

    There is an IPSEC debugging guide here https://doc.pfsense.org/index.php/IPsec_Troubleshooting .

  • IPSec site to site and static routes

    3
    0 Votes
    3 Posts
    889 Views
    C

    Thank you,

    I did a test and worked fine.

    Best regards

    Kostas

  • Need to NAT private IPs to public IPs over IPSec

    2
    0 Votes
    2 Posts
    613 Views
    dotdashD

    @ttblum:

    I believe pfSense does have the feature to NAT over IPSec in this way.

    There is a BINAT option in the phase2. I haven't tried using public IPs, but it should work.

    @ttblum:

    I don't have very many public IPs available to use, can I pick some random IP addresses from a foreign country's IP space that we're not likely to communicate with?

    That's not gonna work, they have to be your public IPs.

  • IPSec - Keepalive

    2
    0 Votes
    2 Posts
    1k Views
    D

    I have the same exact issue.  pfSense ipsec to Cisco ipsec.  It's configured to use BINAT.  I have a pingable host in the field Automatically ping host.  But pfSense does not keep the VPN alive.  I have to start pinging from a host on the network before the VPN will establish.

  • IPv6 only VPN

    4
    0 Votes
    4 Posts
    3k Views
    M

    Well, got it working.
    I tried over from another pc, which has a true IPV6 address.
    I can now setup the IPv6 OpenVPN tunnel.
    Also I can now access IPV4 resources on the LAN, Through the IPv6 tunnel.

    I gave up trying through Teredo

  • IPSec site to site with Cyberoam UTM

    2
    0 Votes
    2 Posts
    1k Views
    E

    You can use the ping host functionality which will trigger that.

  • 'private key not found' when connectin IKEv2 with imported certificate

    3
    0 Votes
    3 Posts
    2k Views
    E

    Normally you have imported even the private key in pfSense right?

    Can you make sure of that?
    Also can you check if the private key has been put on /var/etc/ipsec/ipsec.d/private?

  • How to pass-through PFSense about IPSec from Linksys RV042

    2
    0 Votes
    2 Posts
    894 Views
    S

    Who can help me?

  • NO_PROPOSAL_CHOSEN issue

    13
    0 Votes
    13 Posts
    16k Views
    S

    Is this the issue I've been having?

    https://redmine.pfsense.org/issues/4719

  • Problems with DNS resolution across VPN

    1
    0 Votes
    1 Posts
    969 Views
    No one has replied
  • Weird act of ikev2 on pFsense 2.2.2 and 2.2.3

    8
    0 Votes
    8 Posts
    1k Views
    W

    And yes, afterwards - its Cisco bug related issue…

    https://redmine.pfsense.org/issues/4704

  • StrongSwan: strict CRL policy

    2
    0 Votes
    2 Posts
    1k Views
    S

    Sorry, question is irrelevant now. After some careful thinking, i realized that this will be impossible.

    At first, i thought i will need to make CRLs from endpoint service CA, which i installed specifically for IPSec certificates publishing, available from WAN for checking, which i can do.

    But i realized, that in case of strict check, StrongSwan will require all CRLs available - from root and intermediate CAs too. Those i don`t want to publish to WAN.

  • IPsec kernel panic when enabling MSS clamping

    10
    0 Votes
    10 Posts
    2k Views
    E

    I can reproduce it by clean installing pfSense, enabling IPsec and activate mss clamping. No more webgui, no more ssh as soon as I submit. I tried searching the logs via an attached display and keyboard but could not find anything suspicious.

  • Aes-ctr for fast crypto

    1
    0 Votes
    1 Posts
    590 Views
    No one has replied
  • IPsec tunnel - Large BDP Link, Congestion Algo. & Window Sizes?

    2
    0 Votes
    2 Posts
    725 Views
    E

    Yeah the hosts need the tunning since they generate the traffic IPsec cannot do much here.

  • Large Subnet Routing Issue

    4
    0 Votes
    4 Posts
    1k Views
    V

    I found the issue, was a typo on my site with the subnet masks in one of my aliases I used in a firewall rule.

  • IPSEC traffic going over WAN vs Tunnel

    18
    0 Votes
    18 Posts
    3k Views
    V

    Hi,

    I just saw it myself :)
    I have a typo in my aliases I put in a /16 instead of /12 in my private network alias for 172.16.0.0

    Thanks for your help ermal

  • IPsec mobile clients

    2
    0 Votes
    2 Posts
    800 Views
    E

    AS it is today there is not yet the binding of a specific user to an ip for mobile clients.
    That would allow you to perform that.

    It is possible in the underlying software but is not exposed to the GUI.

  • L2TP/IPSEC setup

    3
    0 Votes
    3 Posts
    2k Views
    T

    You mean aaa.aaa.aaa.aaa and so on?
    These are only for anonymizing, the log contains correct ip's.

  • L2TP/IPSec didn't work well

    3
    0 Votes
    3 Posts
    763 Views
    Z

    I enable mobile clients on ipsec tab,is it possible that I have set something wrong in the rules->IPSec tab?

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.