• [RESOLVED] Latency issues when high throughput over IPSEC tunnel

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    A
    I resolved the issue today. Just in case anyone else has this issue, my problem was solved with a simple BIOS update. I had always noticed a "CPU Microcode error" when booting the system, but I had never thought much about it. When I noticed that the microcode was used for TX/RX Checksum offloading, I decided to update the BIOS and try to resolve the "CPU Microcode error". This also gave me the added benefit of exposing all 4 cores to the OS, whereas only 2 processors had showed previously.
  • IpSec - poor performance in one direction

    Locked
    8
    0 Votes
    8 Posts
    7k Views
    R
    Just to follow-up on this… Turns out, the internet link was 10M/768K instead of 4M/4M.  So, pfSense and the Cisco ASA were working exactly as they should worked. Thanks again Jim for all the help/pointers...
  • Automatic IPSec backup when primary route doesn't work

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    jimpJ
    In the kind of setup I mentioned, the tunnel would be up all the time exchanging ospf info with the far side making routing decisions. It wouldn't be offline.
  • IPSEC site-to-site doesn't work after phase2 sa expired

    Locked
    1
    0 Votes
    1 Posts
    4k Views
    No one has replied
  • Avaya 5610 > PFSense error

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    K
    I'm having the same issue.  Would love to know if anyone has made this work.
  • Comcast DOCSIS 3.0 service Upgrade 50X10 Service IPSEC Fails

    Locked
    6
    0 Votes
    6 Posts
    6k Views
    R
    This isssue has been solved.  In the old router with Comcast I was doing double nating.  Having  a DMZ zone in the middle between their router and my pfSense. Finally after level 2 Support called me back from Comcast DOCSIS 3.0 router does not support the double Natting. Removed the DMZ zone in the middle and got true public IP address on teh WAN interface of pfSense and set bridge mode on the DOCSIS 3.0 Modem with Comcast and everything is happy happy now. Moral of the story don't turn on NAT with comcast put thieir router in Bridge mode by during off NAT, DHCP and DMZ Zone.
  • Site-to-site tunnel in transparent mode?

    Locked
    4
    0 Votes
    4 Posts
    5k Views
    ?
    Not the way you have your network laid out.  Honestly, re-working it really wouldn't be that painful.  You would either configure your router to pass traffic transparently, and then have your LAN interface on pfSense be 8.8.8.1/24 (I hope you're not actually using this network space on your LAN), or you could keep the network configuration basically the same and double-NAT on pfSense and your router.  Alternatively, you could advertise routes to the remote network using 8.8.8.5 as the gateway. Each of these options has merits and drawbacks depending on the size of your network how things are set up inside it.
  • Packet filter on IPSEC Tunnel

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    ?
    If you disable all packet filtering, you're turning pfSense into a straight router and it'll kill all your firewall rules.  Don't do this. If you want to filter inside your IPSEC tunnel, create firewall rules on the ipsec tab at each end of the tunnel and filter what you want.  Remember that rules are evaluated by the interface which sees the traffic, meaning you're filtering on the receiving end of the tunnel.  If you want to stop traffic from ever making it to the tunnel, create the rules on the LAN interface with the destination network being your remote subnet.
  • 0 Votes
    3 Posts
    5k Views
    T
    bradenmcg, Can you post how your PA2020 is configured for the pfSense tunnel?  I am trying to connect a PA2050 to a remote pfSense and keeping getting a timeout error. Thanks, Jeff
  • Site to Site VPN Priority

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    jimpJ
    That won't work with normal routing. It doesn't handle that situation. However you might be able to make it work if you run a routing protocol like OSPF on each node.
  • VPN ok, but no traffic on it…

    Locked
    20
    0 Votes
    20 Posts
    15k Views
    P
    Ok… You're in an exception and this is not a security hole. If you use only "any" as source, it could be a security hole but not with authentication. BTW, good news your tunnel is working.
  • Meaning of "received broken Microsoft ID: FRAGMENTATION"

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    P
    Same here. Would love to know what it means, even if it is benign.
  • Remote Subnet

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    R
    I think a second tunnel is the only way to make this work.  also, 2.0 now supports multiple P2 tunnels. Roy…
  • IPSEC VPN expires

    Locked
    2
    0 Votes
    2 Posts
    9k Views
    R
    I believe the phase 1 lifetime should be larger than the phase 2 lifetime.  also, have you tried "Prefer old IPsec SAs" under "System: Advanced functions" ? Roy…
  • IPSec tunnel to virtual IP

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Simple vpn site to site

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    ?
    IPSEC being set up will handle the routing properly between the two protected subnets.
  • IPSEC Tunnel from LAN to Virtual Server

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    J
    I have a similar setup and am having the exact same problem…anyone out there have suggestions?
  • MOVED: Open VPN easyrsa setup fails

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • 1.2.3 RC3 - Site to Site - NAT-T appears to work! but only pings one way

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    R
    Ok, just tried it with a 1.2.3 Release box and I get the same story!
  • Static route VPN overide

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.