• 0 Votes
    4 Posts
    3k Views
    jimpJ

    ok, I committed a fix to skip that part of the code if there are no p2's.

  • Is this possible to disconnect ipsec mobile users

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    G

    ok cool, Thanks.

  • Can't reach host via ipsec tunnel

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    P

    Strangely enough, it was only a lifetime mismatch for phase 1.
    So finally we're connected, all is fine!

  • IPsec not working, time out & "Unknown Gateway/Dynamic"

    Locked
    8
    0 Votes
    8 Posts
    11k Views
    P

    Now this is interesting!
    I'm starting a new thread about this character problem, it might be useful.

  • Ssh inside an ipsec tunnel

    Locked
    5
    0 Votes
    5 Posts
    5k Views
    L

    @gordslater:

    If this happens from only one machine, I've had a faulty NICs (both onboard and PCI/PCI-X) give me SSH broken pipes and strange problems when I ran  ncurses commands,  top  or a command like  ls -al  with significant return data, yet simple on-liners with no output worked just fine. Drove me crazy each time.

    My SSH sessions stay up indefinitely over the VPN otherwise, no problems

    Yeah stuff like that can drive any one crazy.

    Regarding my problem got solve a couple of days ago. It was the problem from the third party
    they had some bad hardware installed that messed things up.
    Now I have everything working perfectly :)
    thanks PFSENSE :D

  • Pfsense 2.0 <–-> 2.01 IPsec VPN

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    Z

    @cmb:

    The IPsec rules control what traffic is permitted inbound from the VPN, it's always required if you want to permit any traffic in over the VPN.

    Thank you.  That helped.  I was perplexed as my VPN pfSense <–-> IPCop* was working from the pfSense network to the IPCop network.  (And that is the direction of most traffic) But when I checked the network from IPcop to pfSense it was was not working.

    I added some IPSec firewall rules in pfSense and things started working fine!

    Thanks again.

  • Site-to-Site PFSense 2.0 <-> Netgear FVG318

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    D

    I found out with the tipps on  http://doc.pfsense.org/index.php/IPsec_Troubleshooting

    it worked as a charm!

    if u need some help about that give me more details about your issues…

  • Allow ipsec remote network from pfsense itself

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    M

    pufff as it's in front of me - thanks a lot!
    can you remove this thread again as it was just my stupidity? :)

    cheers
    josh

  • IPSec site-to-site and DNS

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    M

    Got it working now, seemed to be an AD DNS problem with Reverse lookup zones that weren't configured.
    Somehow nothing worked untill that was configured.

    Thanks anyway :)

  • IPSEC throughput

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    marcellocM

    Check with your provider if there is no Qos applied to IPSec or any other protocol.

  • Can ping routers but NOT computers on IPSec tunnel remote sites

    Locked
    7
    0 Votes
    7 Posts
    6k Views
    B

    Try disabling the firewall on the computers. Even though you cannot ping them, can yopu remote desktop to them? I found that windows 7 and XP can nativly block ping replies, especially from different subnets. Turn windows firewall of and then try to ping. You can create an exception in windows firewall to reply if you decide you want to leave it on.

  • Is this possible ipsec VPN with DSL modem

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    Z

    Hi,
    If you put a PFsense behind the modem in a DMZ then yes IPSEC VPN should work just fine. Even better would be to get a full bridge modem like a Draytek Vigor 120.

  • IPsec & IPhone again

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    M

    Maybe your 3G provider is blocking Ipsec traffic? Most 3g providers use some kind of proxy for web traffic and ports for VPN are most of the time blocked. You can also try to connect with your wifi connection (if you have one) to see if your config is ok.

  • Pfsense 2.0.1 VPN to Pfsense 2.0.1

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    C

    http://forum.pfsense.org/index.php?topic=41617.0

  • IPsec LAN to LAN tunnel not working without corresponding firewall rules?

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    C

    Yea totally agree. I remember when i thought that when i first intalled Pfsense.

  • IPSEC Mobile VPN return route issue

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    K

    So how can we help to nail down the source of this problem?  I've gotten a little more knowledgeable since my last post, but I'm still not completely there.  If my understanding is correct a packet entering the LAN interface would be sent to racoon at some point to see if it matches any of the SPDs.  If it does, racoon sends the packet into the appropriate tunnel.  If not, it should pass the traffic on through the normal process.

    If this is a correct understanding then the packets in question are disappearing inside pfSense because racoon is for some reason silently dropping the packets rather than doing what it is supposed to do.

    It seems that there would be two possible causes of this problem:

    1.  These packets are being translated by NAT before they are sent to racoon, which would cause them not to match any SPDs.

    2.  There is some subtle error in racoon that causes it to not see the match - perhaps because of a logic error regarding the 0.0.0.0/0 specifier in the SPD.

    If someone will point me in the right direction, I will read and/or instrument the code and see if I can find the problem.

    One other question:  Does anybody know if there is any way to turn on logging for NAT rules.  This would be helpful also in understanding packet flow inside pf.

    Thanks.

    -Dave

  • Using Cron to stap and restart IPSEC service

    Locked
    16
    0 Votes
    16 Posts
    21k Views
    marcellocM

    The second post of this thread shows the link to script thread.

    @marcelloc:

    You can use the script on this topic with few modifications.

    http://forum.pfsense.org/index.php/topic,42025.0.html

  • HELP PLZ! IPSEC Mobile

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Can I check my public ip. Is it real or simple NATing?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • IPSec Tunnel and Block perticular network

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    marcellocM

    action: deny
    proto any
    source any
    destination network 10.0.0.0/8
    description: retrict access to 10.x network

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.