• IPSEC passthrought transparent pfsense

    3
    0 Votes
    3 Posts
    1k Views
    K

    Hello iamzam,

    thanks for your reply. I've added the rule to allow AH but it also didn't work.

  • Azure to pfSense IPSec Tunnel - DNS issues

    4
    0 Votes
    4 Posts
    1k Views
    N

    …and with that response, I honestly figured it out.  Sheesh!  Why didn't I remember to allow UDP across my tunnel?  DNS works fine now.  Thanks!

  • Route traffic between multi IPsec tunnel with NAT

    1
    0 Votes
    1 Posts
    894 Views
    No one has replied
  • LDAP xauth + IPSec

    21
    0 Votes
    21 Posts
    15k Views
    C

    Follow up:
    When debugging and redacting previous post I've disabled a second IPSec tunnel (one for point-to-point VPN, not mobile clients) and now mobile client access seems to work just fine (using Shrew Soft VPN Connect software and builtin iOS client).
    ("Unknown Gateway/Dynamic" log message is still there though)

    I'll look into the settings of this second tunnel later (time to confirm that at least everything is OK with one tunnel).

  • Need ability to support 50mbit throughput with VPN

    4
    0 Votes
    4 Posts
    1k Views
    J

    @kapara:

    Been doing some research on AESNI and it looks like even using a corei5 proc can provide significant improvement.  Anyone test AESNI on pfsense yet?

    Yes, don't bother.  AES-NI makes no difference at this point, though I wouldn't buy a CPU without it as better support is in the pipeline.

  • Slow IPSec VPN pfSense to pfSense

    1
    0 Votes
    1 Posts
    954 Views
    No one has replied
  • IPSec authentication using Active directory

    3
    0 Votes
    3 Posts
    1k Views
    P

    I would suggest checking that you have correctly specified the Search Scope and Base Containers properly.

    PM me if you still have troubles - I have the Microsoft AD part of IPSec working, but now I'm getting asymmetric routing I suspect. :(

  • Best VPN option for AD/RRAS?

    3
    0 Votes
    3 Posts
    1k Views
    C

    Aye, that may be. We've got a heavily virtual environment so for us its zero marginal cost to spin up another VM for that purpose. Though I am intrigued by OpenVPN. That it can export a setup executable is really cool. I might just go with that instead.

    Other thoughts?

  • Ipsec passive on

    4
    0 Votes
    4 Posts
    1k Views
    V
    chflags schg filename

    If you want to be sure that command changed attributes correctly:

    ls -lo filename

    -rw-r–r--  1 root  wheel  schg 193 Aug  1 09:20 filename

    After, if you need to change it again, it will be sufficient to remove protection attributes with:

    chflags noschg filename
  • IPsec Tunnel initiates on wrong interface.?

    2
    0 Votes
    2 Posts
    742 Views
    jimpJ

    Do both of your WAN interfaces have the same gateway, perhaps?

  • On and Off again VPN using IPSec

    3
    0 Votes
    3 Posts
    1k Views
    O

    I am having the same problem with this, it will not re-establish from CISCO side, no problem from pfsense to CISCO site

  • IPSEC VPN not connecting automatically from main site

    1
    0 Votes
    1 Posts
    730 Views
    No one has replied
  • New VPN - no traffic

    5
    0 Votes
    5 Posts
    1k Views
    ?

    I lately had repeated problems with IPsec tunnel (well doing over months), that after the provider did some "service" the tunnel was not functional (no ping, no data passing) for some hours, although the tunnel was successfully established according to racoon protocolls on BOTH sides.

    Strange, strange, maybe NSA had no capacity to handle more man-in-the-middle? :)

  • PfSense IPSEC and H.323 Avaya IP phones not routing

    4
    0 Votes
    4 Posts
    1k Views
    D

    I've put accept on all interfaces and log, but no logging of drooped or accepted udp packets.

    At closer look to the UDP packets I could see that the frame header has the 802.1Q part with VLANID 0.
    The old router accepted this packets, but not pfsense.

  • Configure an IPSec VPN client?

    2
    0 Votes
    2 Posts
    872 Views
    M

    I'm honestly surprised that they can block OpenVPN. We have ours setup so it tries UDP on a weird port –- If that doesn't work it will revert to TCP port 443 so it is very difficult to distinguish from HTTPS.

    Even if you can't make a tunnel with SSH, I'm sure you can make an SSH tunnel back to a server that can handle SSH tunnels. Honestly we stopped handling OpenVPN on PFSense due to everyone being disconnected when the firewall fails over.

  • IPSEC with 3 sites and routing between them

    7
    0 Votes
    7 Posts
    2k Views
    M

    @craggy:

    I've tried everything I can think of but no way can I get this to work.
    no matter what I do I cant get a second phase 2 to come up when it uses a subnet that doesn't directly exist on a wan or lan interface.

    is this a bug in pfsense 2.1 or am I doing something stupid?

    please can someone help, I really need to get this working.

    Another way to do this would be to use a larger subnet on the first Phase 1 of the WAN.

    I.E.

    You have 3 networks:

    192.168.100.0/24 A
    192.168.101.0/24 B
    192.168.102.0/24 C

    So when you setup the phase 2 for A to B, on the B side you set the remote WAN to 192.168.0.0/16

  • Ping host connected with OpenVPN to host IPsec

    3
    0 Votes
    3 Posts
    1k Views
    B

    Worked perfectly!
    A thousand thanks for your help!

    Kind regards
    Beach

  • IPSEC VPN - (Level beginner)

    3
    0 Votes
    3 Posts
    1k Views
    D

    First of all turn OFF the Windows firewall, then test something.

  • A new VPN engine in PFsense

    3
    0 Votes
    3 Posts
    1k Views
    keyserK

    Hmm, that looks like a fairly dead end…

    Well, i'll have to go with openVPN then.

    Thanks.

  • IPSEC Site to Host

    1
    0 Votes
    1 Posts
    614 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.