• Racoon.conf read error???

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    D

    Thank you! I was working with site-to-site VPN so intently I didn't even think to look at the mobile VPN page.  All is well now.

    Thanks again!

  • Example: pfSense and Openswan (mobile pfsense, gateway-to-gateway)

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • SOLVED!!!!!! VPN betwen pfsense 2.0.3 and IPCop 1.4.21

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    T

    Sloved it was beacouse ipcop firewall which already had that connection with another ip cop so i try to connect to another location and it works i think i need to restart this ipcop to clean his memory and it should work.

    THX

  • Racoon crashes on v2.0.3.

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Need help with IPSEC VPN Phase 2 not coming up

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    A

    Ok, then can PFSense handle having Phase 1 and Phase 2 in the same subnet? 
    On the local side the p1 IP = CARP VIP (WAN if)  p2 IP = IP Alias VIP (WAN if)

    NAT 1:1 WAN if
    WAN rules created
    IPSEC rules created

    Still does not come up.

  • IPSEC P2P advice needed

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    M

    I have now managed to get what I can assume is a stable connection between both locations using IPSEC..

    I am just a bit lost how to resolve remote hostnames.

    I have added a remote device on location 2 to a computer on location 1 hosts file and I now can ping across the IPSEC tunnel to that device.

    I am guessing I now need to look at some sort of DNS that will resolve hostnames automatically and accessable from both locations as adding hostnames will be a bit of a pain.

  • IPSEC Not Working With This Conf.

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Ipsec vpn with iPhone

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • New guy trying to got ipsec to work on my phone.

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Peer Identifier except Address does not work

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    B

    Double, Tripple and more Times checked. Another try this morning with DN, but always

    ERROR: couldn't find the pskey for ERROR: failed to process ph1 packet (side: 0, status: 6).

    Luckily this is the only Site2Site with Dynamic IP on the Remote Site. I changed all other Tunnels to
    Peer identifier = Peer IP address
    to make them work.

    Has anyone successfully established a Connection between PfSense 2.0.2 and Linux Openswan U2.6.21/K2.6.30.10-105.2.23.fc11.i586 (Fedora 11) or an LANCOM Box with an Peer identifier other than Peer IP address?

  • Large amount of data over IPSec breaks network/NAT

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C

    That sounds a lot like what would happen if your sync process started going nuts with huge numbers of connections and maxes out the state table. Check your RRD States graph vs. your states limit.

  • VPN stops working, one endpoint drops ESP/ISPKMP packets

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    D

    Thanks!

    So in this particular case when this issue cropped up, I had 2 VPNs drop between 3 pfSense machines.

    FW-A: Single pfSense box
    FW-B: HA pfSense boxes
    FW-C: HA pfSense boxes

    There are 2 IPsec VPNs: 1 between FW-A <-> FW-B and 1 between FW-A <-> FW-C.

    I did find that the "Disable all auto-added VPN rules" was enabled on FW-A and FW-C which is now disabled, but the setting was already disabled on FW-B.

    Looking at /tmp/rules.debug under "VPN Rules" I see rules on both FW-A and FW-C, but none under FW-B. Any idea why? I've double and triple checked the "Disable all auto-added VPN rules" setting and did note that when enabled, a comment under VPN rules is noted as disabled so I know the setting is being noted.

  • Dual WAN VPN implementation - suggestions welcome

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    D

    Recent snapshots offer IPsec failover capability (using gateway group), however you might find it better to migrate to OpenVPN and OSPF.

  • Button Connect VPN on ipsec

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    W

    I understand, thanks cmb!! thanks jimp!!

  • Pfsense 2.02 Ipsec VPN goes down randomly

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C

    "racoon: ERROR: phase1 negotiation failed due to send error" is what happens when you have a misconfigured PPTP server and a client disconnects. PPTP server should never use an assigned IP of any sort, especially WAN, as its server IP.

  • Gateway to Gateway with IPSec not working

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    M

    I spoke too soon.  While the link you provided is correct in that this will allow the gateway to directly connect to systems on the others side of the VPN, it also appears to be causing routing issues for every box that is not the gateway when it's enabled.

    Prior to adding the static route according to the link, I can ping any system (on B network) from my desktop (on A network), however, any attempt to ping a system (on B network) from the gateway (on A network) itself will fail.

    If I then add the route, I can ping any systems (on B network) from the gateway (on A network), but my desktop (on A network) can no longer ping any systems (on B network).  I have noticed that sometimes it appears as though one packet "slips by" but from that point on it's destination host unreachable… oddly, the response is coming from my desktop's IP (not any gateway).

  • How to restart racoon from watchdog script

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    T

    Hi,

    I'm running 2.0.2 with racoon 0.8.0.

    The right combination of loss of connectivity to remote endpoints seems to be triggering the crashing.

    I've submitted a bug report here:

    https://sourceforge.net/tracker/?func=detail&aid=3603844&group_id=74601&atid=541482

    I also submitted this to FreeBSD a while ago, but it got closed.  Should I open up a new one?

    http://www.freebsd.org/cgi/query-pr.cgi?pr=168104

    It seems like the more Phase1's not establishing, the more likely racoon is to segfault.

  • IPsec overhead

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Somoene Help! No traffic going via IPSEC tunnel

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    T

    I am by no means an expert. But since the experts have not had time to respond, I thought I'd give my two cents as I've had a pfsense site to site ipsec tunnel working for sometime.  In phase 2 what did you put for local network and remote network.  I have local subnet selected for the first and the address  ip for the remote network.  I believe this sets up the routing needed from one subnet to the other.  Since you are going from WAN interface to another router as your default gateway, there was an entry in the pfsense guide that mentioned you might have to setup static routes from one network to the other. For your layout, pfsense is not the gatway router.  There are some considerations in the guide for that. I'm not sure if posting from the guide is allowed for copyright reasons. I will try to summarize.  A static route could be entered into the gateway router that will redirect traffic destined for the far side of the tunnel to the pfSense router.
    There may be some issues with this and it goes on to recommend that pfsense be made the default gateway of both networks.  I hope this helps.  FYI, both ends of my tunnel have pfsense as the gateway.  I hope this helps.

  • Issue with connecting to IPSec VPN

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    ?

    Oddly enough I had this exact error and happen to have UPnP enabled. Though my work around was to change "My Identifier" to Dynamic DNS instead of My IP address.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.