• IPSec Tunnel randomly jams

    4
    0 Votes
    4 Posts
    586 Views
    RM85R

    @RM85 image.JPG

  • Phase 2 - Mixing VTI/Tunnel Mode

    1
    0 Votes
    1 Posts
    265 Views
    No one has replied
  • Fragmentation issue on IPsec VTI tunnel

    3
    0 Votes
    3 Posts
    2k Views
    D

    In case anyone finds this thread while diagnosing the same problem. A fix is currently in development, and can be manually applied for testing now. Please see https://redmine.pfsense.org/issues/14396

  • Charon becoming unresponsive

    37
    1 Votes
    37 Posts
    8k Views
    jimpJ

    Yes, it's been fixed in current development snapshots of CE 2.7.0 already, and in the most recent release of pfSense Plus software.

  • Can't connect to IPSEC from Windows.

    1
    0 Votes
    1 Posts
    166 Views
    No one has replied
  • Gateway duplicates usage example

    21
    0 Votes
    21 Posts
    3k Views
    J

    JFYI. I've ended up with adding two extra pfsenses (for HA) that deals with ISP channels only

  • PFSENSE + IPSEC + NAT

    2
    0 Votes
    2 Posts
    492 Views
    A

    I have also posted this problem in the NAT section with more information to see if someone can help me.

    Thanks you

  • IPSEC is insanely slow, Less that 1/10th speed

    3
    0 Votes
    3 Posts
    546 Views
    S

    @Dobby_ said in IPSEC is insanely slow, Less that 1/10th speed:

    This should be the bottleneck

    At least, from B to A. 35 Mbps is about 4 MBps max, but OP says that's 3 so OK.

    @calmasacow How is this test transfer happening? SMB is slow over VPNs unless it's using SMB 3, as I recall. Try FTP or another method if possible. (also Windows 11 has a bug in the May update causing very slow VPN performance but I'm pretty sure that's with Windows 11 itself as the VPN client)

  • Settings from Sonic Wall

    3
    0 Votes
    3 Posts
    430 Views
    M

    @calical https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/configure.html

  • multiple phase 2 to the same destination but different source

    2
    0 Votes
    2 Posts
    324 Views
    N

    recreated in a different order and now it works. first the phase2 without NAT and then the one with NAT.
    Topic can be closed

  • Manually delete ipsec leftovers

    1
    0 Votes
    1 Posts
    257 Views
    No one has replied
  • IPSEC/Charon crash on 23.01

    2
    0 Votes
    2 Posts
    385 Views
    jimpJ

    Hard to say what that crash may have been but probably hit a bug in strongSwan more than anything.

    It should be more stable on 23.05. Not only is it on a newer version of strongSwan, but the new version also fixes some locking issues that had sometimes caused charon to end up deadlocked.

  • Can't get IPSEC to connect, been trying for days.

    2
    0 Votes
    2 Posts
    507 Views
    R

    @sunka said in Can't get IPSEC to connect, been trying for days.:

    May 22 18:29:01 martin-Legion-5-15IAH7H charon: 16[ENC] parsed IKE_AUTH response 1 [ N(AUTH_FAILED) ]
    May 22 18:29:01 martin-Legion-5-15IAH7H charon: 16[IKE] received AUTHENTICATION_FAILED notify error

    This suggests that part of your handshaking is wrong.
    SSLs or keys or a mix of the two or whatever the config is.

  • Portforwarding on WAN Interface via Site to Site IPsec

    12
    0 Votes
    12 Posts
    1k Views
    V

    @operaiter said in Portforwarding on WAN Interface via Site to Site IPsec:

    I did just double checked the rule. Furthermore I did setup a new rule with different traget and port. Still cant see outgoing traffic on pfSense interface.

    The only reasons for this apart from NAT and filter rules, I can think of, is that the tunnel is not working properly.

    Possibly the additional phase 2 is not correct or not accepted. Some IPSec implementations may reject this multiple phase 2 for the same or overlapping subnets.
    You can check out the log for hints due this.

  • Rediscovered old workaround for IPSec DNS still works

    2
    2 Votes
    2 Posts
    659 Views
    R

    Same story for me on pfSense+ 23.01. Tried everything until I came across this post, which amazingly works. My use case is to iOS 16.4.1.

  • Strange VTI Routing issue

    6
    0 Votes
    6 Posts
    861 Views
    M

    @meluvalli For now, I ended up switching to WireGuard. I much prefer to use IPSec though. IPSec seems more stable of a connection. I really would like to get to the bottom of this :(

  • IPSEC tunnels up, won't pass traffic

    1
    0 Votes
    1 Posts
    228 Views
    No one has replied
  • Locally generated traffic not flowing into IPsec site-to-site tunnel

    3
    0 Votes
    3 Posts
    565 Views
    M

    Seems this is a known limitation: https://forum.netgate.com/topic/118063/dhcp-relay-over-ipsec-vpn/16

  • IPsec + Cisco Meraki

    3
    0 Votes
    3 Posts
    483 Views
    L

    I have solved the issue. The cause was on hoster's network and I had to manually add vpc routes to go via pfsense server for office networks CIDR.

    Also need to add that there was no such issue when we for example use openVPN since it masks the IP and in normal IPsec we have to know exactly where to send packages to. Thus some extra steps have to be done.

  • VPN Probe?

    1
    0 Votes
    1 Posts
    395 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.