• Dual WAN IPSec failover on 3G link

    1
    0 Votes
    1 Posts
    641 Views
    No one has replied
  • Site - Site IpSec http and UDP traffic dies

    1
    0 Votes
    1 Posts
    469 Views
    No one has replied
  • 0 Votes
    3 Posts
    1k Views
    A
    I corrected an important mistake in my last post.  It is the overview ipsec page that shows the incorrect IP (shows the IP Alias instead of the Carp IP).  The SAD page shows the correct IP (Carp IP).
  • Traffic on VPN or gateway ??

    3
    0 Votes
    3 Posts
    869 Views
    L
    my problem is solved. The problem was the opening of the ports on the FW for the ESTABLISHMENT VPN . Port 500 and 4500 was open for the VPN but other port were necessary so the traffic did not pass but the VPN was seen as up .
  • SOLVED: pfSense box can't ping/access systems on Remote Site

    3
    0 Votes
    3 Posts
    955 Views
    N
    Thanks heaps!! that worked perfectly! ;D
  • MOVED: ipsec ikev2 on ios8

    Locked
    1
    0 Votes
    1 Posts
    578 Views
    No one has replied
  • Multi WAN load balance with IPsec?

    3
    0 Votes
    3 Posts
    1k Views
    C
    NAT has nothing to do with it. NATing IPsec connections is possible, but it does nothing for this scenario. It'd have to be routed in a means that isn't currently supported with IPsec. Might be possible with MLPPP over OpenVPN.
  • PfSense 2.2 to ASA 8.2 site to site not passing traffic

    4
    0 Votes
    4 Posts
    2k Views
    B
    @filnko: Have you tried today's snapshots? There have been some recent problems with IPsec under 2.2 Sure enough, one more reboot - did it.  That's exactly what seems to have cured my issue, for whatever reason the NAT statement solved itself after a second reboot. THANK YOU.
  • VoIP issue through IPSEC

    3
    0 Votes
    3 Posts
    1k Views
    B
    At both ends I have allow all rules for IPv4 and IPv6 traffic. From the PBX I can ping the phone, and reach it's web interface. Didn't test from the clients pc on main office Side yet though. Can try that tomorrow.
  • IPSec with LDAP Backend not working

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Vpnc: no response from target

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • (Solved) VPN with Remote ID

    2
    0 Votes
    2 Posts
    1k Views
    S
    it is the field "Peer identifier" select  "IP adress" and enter Remote ID
  • (Solved) IPSEC Host to Host

    2
    0 Votes
    2 Posts
    1k Views
    M
    i have found the solution. The hint in this topic was a great help regarding the NAT. After doing as he advised, it worked straight away https://forum.pfsense.org/index.php?topic=81573.0
  • Asterisk addon package not routing traffic down ipsec tunnel…?

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Force all traffice through Mobile IPSec with multiple subnets / phase2

    1
    0 Votes
    1 Posts
    718 Views
    No one has replied
  • Failover not working

    1
    0 Votes
    1 Posts
    788 Views
    No one has replied
  • Ipsec VPN using one ISP and backup with other ISP

    2
    0 Votes
    2 Posts
    904 Views
    3
    You can achieve this with either a dual-circuit connection (usually fairly expensive) or by updating DNS records. I don't think PFSense has the built-in functionality to update the DNS records if one WAN is down (please feel free to correct me), so you could use a provider like DNSMadeEasy and their DNS Failover. I think you would need to create a gateway group and use it for the IPsec interface. [EDIT] Apparently the DynDNS can use a gateway group too so no need for the likes of DNSMadeEasy. @jimp: It should work fine though for pfSense to pfSense you need both the IPsec tunnel set to a failover gateway group and a DynDNS entry set to the same failover gateway group, and then use that dyndns host as the remote peer address for the other side. Then when WAN1 fails to WAN2, the dyndns IP changes, so the far side knows to accept the new peer, and that's where IPsec will start connecting from.
  • Telnet on port 25 over IPSEC

    1
    0 Votes
    1 Posts
    744 Views
    No one has replied
  • IPSEC Nat Issues

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    In the local network part of the phase 2, put Address and 10.10.10.210. Directly underneath that, put the NAT address to show the other side, 172.16.199.1. For the remote network, if you need to reach all of 10/8, put that, otherwise put in the IP address they gave, 10.120.0.32
  • Make php file to update /cf/conf/config.xml Host IP from IPSEC tunnel?

    1
    0 Votes
    1 Posts
    556 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.