• IPsec Mutual RSA

    3
    0 Votes
    3 Posts
    3k Views
    M
    Dear doktornotor, Thank you very much, that did it! I did rebuild the certificates so that the "O" field does not contain a space to avoid that facet of complexity and than things did just work fine. Regards, Michael
  • Can not get domain over ride to work

    2
    0 Votes
    2 Posts
    858 Views
    jimpJ
    For a domain override, the IP address you give is a remote DNS server that will respond with the correct IPs for items inside of that domain. If that is across a VPN, especially IPsec, you may also need to fill in the source address box for the domain override as your LAN IP
  • Ipsec opt1 wan up but no traffic

    2
    0 Votes
    2 Posts
    1k Views
    A
    anyone could help??
  • PFSense 2.1 IPSEC disconnected after some time

    3
    0 Votes
    3 Posts
    3k Views
    C
    This is broken again in 2.1.2
  • IPSEC tunnel to Cisco ASA 5510 won't work

    3
    0 Votes
    3 Posts
    2k Views
    E
    What about the proxy-id (encryption domain)? The cisco products checks the presence of the proxy id, unlike other vendors as Fortinet or Juniper. Could you post your Phase 2 entries?
  • How Can I create 2 Mobile Client ipsec profiles

    11
    0 Votes
    11 Posts
    2k Views
    J
    @opalit: As it happens I have downloaded that one. When I did a search on OpenVpn in the app store, dozens came up. Most were probably vendor-specific.  There's a lot of VPN providers who made their own app.  You can only use those with that particular vendor.
  • Vpn pfsense to draytek router

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • IKEv2, what would it take to get this?

    3
    0 Votes
    3 Posts
    2k Views
    J
    Hooray!
  • Is VPN broken in 2.1

    8
    0 Votes
    8 Posts
    2k Views
    D
    So, like… how about posting the contents of /var/etc/ipsec/racoon.conf file?
  • MOVED: IPSEC NO PERMITE CONEXIONES PARA SUBREDES

    Locked
    1
    0 Votes
    1 Posts
    589 Views
    No one has replied
  • IPsec passthrough not working with Xbox One

    3
    0 Votes
    3 Posts
    3k Views
    P
    I have been having the same problem. When I just connect my Netgear router, all works well.
  • Multiple subnets/identifiers with Mobile IPSEC?

    4
    0 Votes
    4 Posts
    1k Views
    jimpJ
    None of that really applies to Mobile. There isn't a way in IPsec currently to restrict access for a given IP/PSK in the way you're after. If this is for site to site, use individual tunnels, not mobile. If it's for mobile clients, the Phase 2 entries are only really used if you check the box to supply a list of networks to the client, and then only if they obey that list. Mobile setups let the client specify what they want to send, the server can't really restrict that (except with firewall rules)
  • Identical subnets on client side

    3
    0 Votes
    3 Posts
    1k Views
    H
    Thank you dotdash! I didn't cross my mind that I could set the source subnet (our side) to the customer's server (/32) instead of the subnet. And I will have a look at NAT too.
  • IPSEC passthrought transparent pfsense

    3
    0 Votes
    3 Posts
    1k Views
    K
    Hello iamzam, thanks for your reply. I've added the rule to allow AH but it also didn't work.
  • Azure to pfSense IPSec Tunnel - DNS issues

    4
    0 Votes
    4 Posts
    1k Views
    N
    …and with that response, I honestly figured it out.  Sheesh!  Why didn't I remember to allow UDP across my tunnel?  DNS works fine now.  Thanks!
  • Route traffic between multi IPsec tunnel with NAT

    1
    0 Votes
    1 Posts
    922 Views
    No one has replied
  • LDAP xauth + IPSec

    21
    0 Votes
    21 Posts
    16k Views
    C
    Follow up: When debugging and redacting previous post I've disabled a second IPSec tunnel (one for point-to-point VPN, not mobile clients) and now mobile client access seems to work just fine (using Shrew Soft VPN Connect software and builtin iOS client). ("Unknown Gateway/Dynamic" log message is still there though) I'll look into the settings of this second tunnel later (time to confirm that at least everything is OK with one tunnel).
  • Need ability to support 50mbit throughput with VPN

    4
    0 Votes
    4 Posts
    1k Views
    J
    @kapara: Been doing some research on AESNI and it looks like even using a corei5 proc can provide significant improvement.  Anyone test AESNI on pfsense yet? Yes, don't bother.  AES-NI makes no difference at this point, though I wouldn't buy a CPU without it as better support is in the pipeline.
  • Slow IPSec VPN pfSense to pfSense

    1
    0 Votes
    1 Posts
    983 Views
    No one has replied
  • IPSec authentication using Active directory

    3
    0 Votes
    3 Posts
    1k Views
    P
    I would suggest checking that you have correctly specified the Search Scope and Base Containers properly. PM me if you still have troubles - I have the Microsoft AD part of IPSec working, but now I'm getting asymmetric routing I suspect. :(
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.