• Mobile clients: Phase2 PFS Group influences to ALL IPSEC tunnels

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    J
    Thanks, I had the same problem that all other tunnels (whith different phase 2 settings) no longer worked in phase 2. Disable the global setting "Provide the Phase2 PFS group to clients ( overrides all mobile phase2 settings )" in mobile clients tab has solved it.
  • Selectively routing traffic across IPSEC Tunnel

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    D
    If I may offer a suggestion: In this case just go with OpenVPN. The other options they offer (PPTP, L2TP/IPsec etc) are meant for those using their PCs to connect and prefer not to install 3rd party VPN tools.
  • Host to host in site to site vpn

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    C
    Just do address to address on the phase 2.
  • Unable to login to PFSense Webconfig after IPSec setup.

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    C
    Running "killall racoon" at a command prompt should flush the SPD and leave you able to get back in. At least until something gets touched that restarts it, but if you go straight to the IPsec page and delete or fix the wrong entry and save, you should be good.
  • Access to port 80 over ipsec

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Site to Site IPSEC - Please Help

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • New WAN IP configured and getting "Remote Side not responding" error

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C
    Packet capture on WAN on both sides filtering on port 500. You probably don't have connectivity in one direction for some reason, like if it's a Comcast business cable modem, those usually enable firewalls within the modem by default that would block IPsec inbound from the Internet .
  • Accessing webinterface through ipsec tunnel

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • IPSec Tunnel UP (green) - But cannot ping internal networks

    Locked
    5
    0 Votes
    5 Posts
    7k Views
    G
    Hey Brian, I've got a similar issue, though mine seems to be the inverse of yours. I can ping hosts from PFSense, but PFSense is refusing to send logs over the tunnel, and I can only ping in one direction, not the other. When I ping an internal host from my data center, it tries to be sent out the WAN hole instead of going across the Tunnel. Do you have any bright ideas on this, seeing as you managed to figure your issue out? My thread is here - http://forum.pfsense.org/index.php/topic,55900.0.html
  • 0 Votes
    23 Posts
    41k Views
    S
    For whatever reason, racoon segfaults when I run RSA+Xauth after the client sends back the XAUTH_USER_PASSWORD. This doesn't happen with PSK+Xauth oddly. >:(
  • I need clarification about roadwarrior ipsec accounts.

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Outlook/Thunderbird Stalling

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    J
    System -> Advanced Misc. Turn on MSS to limit the VPN traffic to 1400 (leave blank for this value). Fixed my issue. W00h00 :O)
  • Sasyncd status?

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    E
    The problem with it are the not supported synchronization of replay counter in FreeBSD.
  • How to choose outgoing IP for local traffic to ipsec tunnel?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Mobile Clients different rights

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    D
    I see… is there any quick and good guide about that? I tried also to make shrew client connect to a NOT-Mobile_clients tunnel to solve my problem, but I can't succeed. Is this possible in any way? I tried many configurations, and I can actually connect, but I always get this: racoon: ERROR: failed to get sainfo. racoon: ERROR: failed to pre-process ph2 packet [Check Phase 2 settings, networks] (side: 1, status: 1). So the problem should be about local and remote network. I set up a fixed address in shrew client and put the same as remote network and the pfsense lan subnet as local network. I'd like to know if I'm just wasting my time and should try openvpn or if I could solve it. Thanks!
  • Ipsec vpn problem

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    A
    @cmb: Seems you're probably better off posting in the Turkish board, what you posted doesn't make much sense in English and the users on that board can probably help better than us English speakers are able to. http://forum.pfsense.org/index.php/board,47.0.html What you're showing there is just the normal startup log, if that's all you have in your log, nothing is trying to initiate traffic that matches your configured IPsec panpa ben çoktan hallettim yinede teşekkür ederim,yardımların için
  • Racoon PAM + google authenticator

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    K
    this is great!!! I hope this gets included as an option for ipsec clients!
  • IPSec VPN

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C
    http://doc.pfsense.org/index.php/Mobile_IPsec_on_2.0
  • IPSec Site to Site - pfSense 2.01 <> m0n0wall

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C
    It's almost the exact same config screens, match your settings appropriately as explained in the link above, configure rules on IPsec as desired, and that's all there is to it.
  • Ipsec vpn to mikrotik

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.