• IPsec Advanced Settings issue.

    1
    0 Votes
    1 Posts
    683 Views
    No one has replied
  • Ver 2.2.1 & Draytek VPN tunnels

    4
    0 Votes
    4 Posts
    1k Views
    R

    FWIW, I've spent many hours trying to get a reliable VPN between PFSense 2.2.1 and a Draytek with IPSEC. Draytek to Draytek works fine but the PFSense VPN drops out and/or fires up multiple Phase 2's after which traffic doesn't flow :(

    I've tried setting the Draktek as outgoing only/incoming and both and tried telling PFSense to only be a responder. No difference.

    I'd love to know what the trick is.

  • 2.2.1 - Have to reload filter manually after IPSEC tunnel establishes

    3
    0 Votes
    3 Posts
    859 Views
    D

    I am seeing this as well, however I didn't realize that was the problem and was digging into the IPSec connection settings until I ran across this post, stopping and starting IPSec services, etc, reloading the filter is the fix. I haven't figured out anything more on why yet, but now that I know its a filter issue and not an IPSec issue. I at least know where to look now.

  • 0 Votes
    9 Posts
    2k Views
    D

    Good that it works now. ;)

  • IPSec AES256

    17
    0 Votes
    17 Posts
    3k Views
    jimpJ

    @kodimar:

    My research has pointed that the NO_PROPOSAL_CHOSEN error is caused by an error in the Phase 2 settings.  Is this a correct assumption?

    It can be either Phase 1 or Phase 2. See https://doc.pfsense.org/index.php/IPsec_Troubleshooting for help interpreting the logs.

    Best thing to do is set IKE SA, IKE Child SA, and Configuration Backend to Diag in the log settings, all others on Control, and have the remote end initiate.

  • Question about ipsec configuration

    1
    0 Votes
    1 Posts
    635 Views
    No one has replied
  • IPsec Phase 2 kills secondary LAN Link

    17
    0 Votes
    17 Posts
    2k Views
    S

    Ok so I do understand the basics of setkey after I have been reading up on this all day.
    But I can't seem to add any entries.
    It doesn't matter what I type into the command line the only response I get is:
    setkey: No match.

    I am trying to setup the captive portal on the OPT1 interface, but because the interface is not reachable because I have an IPSec tunnel from the interface the captive portal does not work.

    My interface is IP: 10.11.15.1/24

    Could someone please help me out with the command for setkey?

    Thanks

  • IPSec SRX <> PFsense - Tunnel UP no traffic

    3
    0 Votes
    3 Posts
    1k Views
    B

    yes,
    there I created a any-any-any rule so it's not blocked by firewall (normally)

    When I start debug on te SRX side I see that traffic is going into the tunnel, but not coming out on other side :-)

  • ShrewSoft VPN and virtual IP address routing

    1
    0 Votes
    1 Posts
    713 Views
    No one has replied
  • After I update may PFsense Box from 2.2 to 2.2.1 IPsec do not Work

    2
    0 Votes
    2 Posts
    892 Views
    G

    now I check the Virtual IP bug
    look the responder only mode
    and all other points from this Post on last Days.

    I have no clue what ist wong after the update to 2.2.1

    always wrong remote address

    ???

    Thanks for your Help

  • Pfsense and Route-Based IPSec VPN

    9
    0 Votes
    9 Posts
    5k Views
    H

    thanks everyone!
    We use VPN tunnels to a lot of 3rd party devices, including ASA, Fortigate, Sonicwall, Palo Alto, etc. I can confirm that you don't need Route-based or Policy-based on both end, it's only matter locally.
    well, for now, we can go with Policy-based, once there is a need, I'll look into these options again.

  • IPSec PFsense 2.2 To Sonicwall timing out straight away

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Route-based VPN

    1
    0 Votes
    1 Posts
    767 Views
    No one has replied
  • Multi Site-to-Site VPN Issue

    3
    0 Votes
    3 Posts
    944 Views
    S

    I have fixed it. Just restart the Fritzbox. There was no issue in my config.

  • Charon: 06[JOB] deleting half open IKE_SA after timeout

    1
    0 Votes
    1 Posts
    4k Views
    No one has replied
  • FIXED 2.2.1 ALIX <> APU: phase2 get's: traffic selectors inacceptable

    3
    0 Votes
    3 Posts
    4k Views
    E

    Because they do not match!

  • IPsec Phase2 SHA256

    4
    0 Votes
    4 Posts
    1k Views
    D

    Hmmm… so post some logs about how's it now working.

  • PFSense 2.2.1 to Draytek 2860 IPsec multiple Phase 2's being created.

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • IPSEC Mobile Stuck in Mutual PSK + Xauth

    1
    0 Votes
    1 Posts
    587 Views
    No one has replied
  • IPSec VPN include cache & secure proxy !!

    1
    0 Votes
    1 Posts
    511 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.