• /32 SA should have higher precedence than /28 SA

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • 0 Votes
    3 Posts
    3k Views
    F

    here are the rest of the settings

    ![Screen Shot 2011-09-16 at 12.48.02 AM.png](/public/imported_attachments/1/Screen Shot 2011-09-16 at 12.48.02 AM.png)
    ![Screen Shot 2011-09-16 at 12.48.02 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2011-09-16 at 12.48.02 AM.png_thumb)
    ![Screen Shot 2011-09-16 at 12.44.23 AM.png](/public/imported_attachments/1/Screen Shot 2011-09-16 at 12.44.23 AM.png)
    ![Screen Shot 2011-09-16 at 12.44.23 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2011-09-16 at 12.44.23 AM.png_thumb)
    photo.PNG
    photo.PNG_thumb

  • IPhone IPSec AT&T Fail?

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    jimpJ

    Try setting NAT-T to force on the server side. It may have better luck breaking out of their network.

  • HELP!!! IPSEC Failover

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Racoon.conf file error / block every tunnels below

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    D

    You may want to submit a report to http://ipsec-tools.sourceforge.net/ (and secondary to http://redmine.pfsense.org/projects/pfsense )

  • Do I always need XAuth when using IPsec? (re: iPhone VPN and XAuth)

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    …until someone steals your phone and then has unlimited access to your network...

    The certificate auth, I believe, only replaces the pre-shared key part, not the username/password part.

  • Ipsec to network with multiple gateways

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    R

    Hi, i think i found my answer by playing around a bit.

    My remote network is 10.1.105.0/24, i then added a route on 10.0.0.2 –> route add -net 10.1.105.0 10.0.0.1 255.255.255.0
    then i could access the machines running through gateway 10.0.0.2

    i hope this might help someone else.

    Thanks,

  • IPSec and Mac issue

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Site2Site with dynamic IP without dns

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ

    If you use a dynamic DNS hostname it does work properly - I use this personally and I know people using it with dozens/hundreds of tunnels. It works great.

    However the title of the thread said "without DNS" so that's how I replied.

  • How to monitor Tunnel Uptime?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    You can't really tell that except from reading the full log.

    If you look at the output of setkey -D you can see when the phase 1 entry was created, but if that was ever re-negotiated then you'd only see the latest entry there. (Or perhaps an occasional older one in some cases)

  • Ping Redirect

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    J

    My bad. Thank you for answering.

  • IPSEC VPN throughput calculation

    Locked
    1
    0 Votes
    1 Posts
    4k Views
    No one has replied
  • Phase 1 Negotiation failed due to time up

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • Why no ESP-NULL?

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    jimpJ

    Nobody has ever asked for esp-null to my knowledge, so it's probably lack of demand (and hence lack of funding or submitted code).

    The use cases for it are pretty rare as well.

  • Question about Simple Tunneling with AH

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    M

    I'm going to go ahead and give this topic a little nudge in hopes that someone can shed some light. I've also found a couple of posts like this:

    http://forum.pfsense.org/index.php/topic,29152.msg151679.html#msg151679

    where someone was trying to use AH, and the workaround they came up with was to use ESP.

    I'd really like to use AH, as in the eventual implementation one end of the tunnel will be a low powered device that I'd prefer to not saddle with a bunch of encryption, and in this application confidentiality is not as important as authentication and integrity.

  • IPSec - Shrew Client to pfsense then through tunnel….

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    J

    Hi.

    Thank you very much for your help.

    I have created the tunnel and everything seems to be okay until it stops working with no reason.
    Having a look at other threads of this forum, it seems to get back to work when the racoon service is restarted.

    In other posts it is suggested to check the option "System -> Advanced -> Miscellaneous -> Prefer older IPsec SAs" but in the end I have to reboot racoon service.

    Any help appreciated

    Thank you very much.

  • IPSec was working with 1.2.3 , with 2.0 RC-1 stopped working

    Locked
    5
    0 Votes
    5 Posts
    6k Views
    A

    This is very similar to my problem, our situation and logs look almost identical.

    http://forum.pfsense.org/index.php/topic,40285.0.html

  • Questions about certificate authentication

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    Easy test would be to make a different certificate from a completely different CA and see if you can still get in with that.

  • Strange IPSec site 2 site problem. SOLVED

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    U

    Oki i have solved it and IT was NOT IPsec problem.

    IT was all down to that i HAD NOT set a GW on my access point that i was using to ping test.

    I am now going to go an kick my self a bit, but anyway i have hardened my IPsec skills  :P  ;D

  • Enc0 not routing traffic

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    M

    Then i dont know

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.