• Site to Site IPSEC Tunnel works only one way?

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    jimpJ

    Generally speaking, only two things would prevent traffic from moving.

    1. The tunnel isn't actually up (check status > ipsec)
    2. Firewall rules on the IPsec tab (Firewall > rules) are not allowing the traffic

  • Android 4.0.X, Ice Cream Sandwich to pfSense

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    jimpJ

    Made a liar out of myself just now… Attempted an IPsec PSK+Xauth connection again and it worked.

    Perhaps one of the several firmware updates since the last time I tried it made it work.

  • IPSec works only for one day - "couldn't find the proper pskey"

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    jimpJ

    Try going to System > Advanced, on the Misc tab, and toggle the checkbox for "Prefer old IPsec SA"

    It sounds like when one SA is expiring, it isn't getting fully dropped/rebuilt as expected by both sides.

    Also, disable NAT-T.

  • IPSec Speed Boost Tips

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ

    Probably the CPU… Celeron's aren't exactly known for their high-speed cryptography performance... :-)

  • Route to IPSEC

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    M

    @cmb:

    you have to have a phase 2 matching the OpenVPN tunnel IPs for it to go across the tunnel.

    Tnx, now work :-)

    Manuel

  • IPSEC between Pfsense 2.01 and IPfire 2.11

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Racoon restarts when other interfaces come up or down

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    C

    Reloading (updating its config, as must be done since IPs, etc. can change) is different from restarting (wiping out the SAD, SPD), so no.

  • I am not able to start second phase2 tunnel

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C

    yes it's only a ping. You just need to initiate any traffic that matches the second phase 2. Then if it doesn't come up, check the IPsec logs to see why.

  • IPSec, LAN's can talk, but not pfsense machines?

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    R

    Thanks CMB, that was what I was thinking I might have to do - works great, thanks :)

  • SHA-1 problems to other routers

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    G

    I can confirm that issue with SHA1 and our Watchguard XTM for a Site-to-Site VPN ???

    Crazy to me is that another box running pfSense version 1.2.3 is working perfectly since a long time using SHA1 and same settings (except PSK and WAN stuff of course). It appears as the tunnel is up-n-running but in fact to traffic is going through.

    My solution is so far changing to MD5 instead on both, Phase 1and 2. After that every thing is OK immediately. :o

    Would like to see this can be fixed some how as I don't know if i'm missing a security option or anything alike.

  • IPsec + iOS and DNS Issues

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    E

    it's works for me too but what is this floating rule ?

    thanks

  • IPSEC routing issue and "connect vpn" button missing

    Locked
    9
    0 Votes
    9 Posts
    8k Views
    M

    @pingulino:

    @jimp:

    As I said though, there are some bugs in the detection process for that button, it doesn't take IP aliases or subnets other than lan into account. So unless the local Phase 2 includes the LAN subnet, there is no connect button.

    Does this mean I can not use IPSec for my OPT network?
    That would be disastrous!

    Infact I am not able to make opt1 working with ipsec. Have you made it working?

  • L2TP over IPsec

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    M

    Its Work :)
    I postet on a other Forum from Germany and its work like this:
    http://www.administrator.de/Pfsense_L2TP_over_IPSec.html

    Now i want a Certificate Methode(mutual rsa + xauth) with L2TP over IPSec. Anyone can help?

  • IpSec Routing Problem

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    A

    Call me silly but I do not understand could anyone be more precise

  • Netbios - See, ping or connect to shares across IPSEC tunnel

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    K

    Hey
    thanks for taking the time to reply.. I'll try that out and go from there.. thanks again…

  • Connect a Sonicwall to pfSense VPN

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    K

    Thanks for the reply.. You are correct.. it works 100%

  • Clarification on IPSec and OpenVPN documentation

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    S

    thanks so much! :)

    @jimp:

    That should work fine, what that warning means is that you can't have IPsec and OpenVPN between the same two locations carrying the same two subnets.

    So you can't have:

    Site A:
    x.x.1.0/24
    Site B:
    x.x.2.0/24

    And have IPsec between x.x.1.0/24 <-> x.x.2.0/24 and OpenVPN between x.x.1.0/24 <-> x.x.2.0/24 - identical networks.

  • Routing Problem with IPSec Tunnels (3 different Sites)

    Locked
    8
    0 Votes
    8 Posts
    6k Views
    jimpJ

    Without seeing your exact config it's hard to speculate. Generally speaking, that error means your Phase 2 definitions do not line up.

    For that kind of setup, you end up with something like:
    IPsec A<->B
    192.168.200.0/24 <-> 10.10.0.0/24
    192.168.200.0/24 <-> 10.20.0.0/24

    IPsec B<->C
    10.10.0.0/24 <-> 10.20.0.0/24
    192.168.200.0/24 <-> 10.20.0.0/24

  • L2TP over IPSEC

    Locked
    5
    0 Votes
    5 Posts
    15k Views
    jimpJ

    It is still not possible, and may have to be pushed back yet again for 2.2

    I added a note to http://doc.pfsense.org/index.php/L2TP_VPN_Settings and included a link to the redmine ticket.

  • Possible Bug: IPSEC to OpenVPN conversion

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ

    They should have been removed, yes, when that tunnel was deleted or disabled.

    That commit (which should be in 2.0.1) should have ensured that they were cleaned out if all tunnels were removed, but I don't see how it would leave them in there if the tunnel were removed.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.