• Windows Domain Members/not members access

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • IPsec and iPhone, log ok, status not

    Locked
    9
    0 Votes
    9 Posts
    5k Views
    E
    like i said, many providers and home routers are blocking esp-traffic, therefore nat-traversal could be a solution. since many networks like hotels, etc.. doesnt allow any traffic appart from http(s) via a proxy, even nat-t would fail. i know of a company which does ipsec over https, like you could do openvpn over https, encapsulating the payload in a ssl-header for avoiding these problems, but how this works exactly, i have no idea.. Glad that's running for you..
  • IPSEC on Dual-WAN 2.0RC1 box to Firebox Edge X

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    O
    Thanks for the tip, that did the trick!  :D
  • IPsec Sonicwall VPN Client Issue - Resolved

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • IPsecVPN iPhone no DNS?

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    E
    @szop please be aware that by enabling "Provide a list of accessible networks to clients" you do lose your default route trough your tunnel and all of your traffic apart from the traffic eventually defined in the phase 2 local subnet will NOT be sent trough your tunnel.
  • IPsec Mobile Clients

    Locked
    9
    0 Votes
    9 Posts
    4k Views
    P
    ok.. maybe that will work. but what is with my iOS devices? For them i have to use PSK + XAuth. And this isn´t possible with a second phase 1  :( i forgot to say that i´m using the latest 2.0 RC1 build. edit: ok, now i´m using only PSK´s +Xauth for the roadwarrior connections and it´s working like a charme with greenbow and iOS devices :)
  • Tunnel down with many SAD table entries

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    cfapressC
    As a follow-up to my own post… By enabling the " Prefer old IPsec SAs " my problem has been resolved. The IPSec connection still tries for multiple SAD entries but falls back to the proper number, two. This config option can be found, in version 1.2.3, in the System menu, under Advanced, in the Miscellaneous config options. Jason
  • No webgui after setup ipsec

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Creating a route into ipsec tunnel - is it possible?

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    M
    Thank you, it worked!
  • Site-to-site pfs1.2.3 <-> ASA5510 only one-way traffic

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C
    No under Firewall>Rules, IPsec tab.
  • Pfsense –> Netscreen NS100

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C
    Yes, several times. Just make sure the settings match up.
  • IPSEC tunnels keep going down between 2.0 and 1.2.3

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    A
    DPD off on the 2.0 side doesn't appear to have made any change for us.
  • Tunnel to /23 subnet?

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    jimpJ
    That would do it. :-)
  • Pfsense 2.0rc1 crl ipsec

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    Did you choose the CRL on the OpenVPN server config page? If you make a CRL under the Cert Manager, you still have to tell the OpenVPN instance to use it.
  • Ipsec with overlapping subnets on 2.0

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    jimpJ
    Yeah, that is saying sort of what I said but in a lot more detail. :-) Adding that to pfSense has been discussed, but it's too much work to make it into 2.0.
  • Mac 10.6 native VPN client

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    P
    There will be a manual to set up ipsec with an iPhone and pfsense 2.0 soon, I hope. In the meantime, your best option is using OpenVPN with the OpenVPN export wizard package and Viscosity as OpenVPN client on OS X, as it works flawlessly.
  • IPsec network conflict

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    C
    If you're just NATing all that traffic to one IP within the local subnet, and the traffic matches the SPD before NAT, then you can use outbound NAT on IPsec if using 2.0. Otherwise there has never been a way to accommodate that short of doing the NAT on a different system.
  • IPsec…. should I go v2 or 1.2.3?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • 1.2.3 <–IPSEC--> 2.0RC1

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    E
    same normal tunnel not working for me since upgrade 2.0 RC1,i have to downgrade to 1.2.3
  • HOW TO configure GRE over IPSEC between 2 PFSENSE boxes

    Locked
    8
    0 Votes
    8 Posts
    26k Views
    jimpJ
    Then you should be able to do that with IPsec in transport mode + a GRE tunnel + some routes. No idea how that would work on the Juniper side, but pfSense should handle it fine.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.