• 0 Votes
    1 Posts
    3k Views
    No one has replied
  • Site-to-site VPN assistance

    Locked
    10
    0 Votes
    10 Posts
    5k Views
    jimpJ

    That gets a bit harder to do then. Again, it should be possible in 2.0 but not in 1.2.3

    In 2.0 you'd just assign the OpenVPN interface as an optional interface, then add a gateway that says it's on that interface, with an IP of the other side of the OpenVPN tunnel.

    Then add a rule on the LAN side that matches the IP(s) of the devices to re-route, with a destination of any, with that gateway chosen.

  • PfSense IPSEC and H.323 Avaya IP phones not routing

    Locked
    6
    0 Votes
    6 Posts
    7k Views
    O

    Hello  sir

    Now I try to set up IPsec Box with Pfsense for H323 avaya IP phone too, I have already  config for IPSec Mobile client  but I found
    the status of IPSec it show the yellow creoss sign not  GREEN , How I can enable this service. But I make sure I have already checked enable IPsec and IPsec Mobile client .

    Thank you

  • ERROR: failed to pre-process packet.

    Locked
    8
    0 Votes
    8 Posts
    9k Views
    jimpJ

    Not sure what else you might want to try in that case.

    Some people have had luck switching hashes or encryption algos with certain devices (e.g. if you're using SHA1 in either phase, use MD5 instead, or vice versa)

  • IPSec and Windows File Sharing

    Locked
    20
    0 Votes
    20 Posts
    14k Views
    P

    Thanks submicron UDP did solve the problem. I'm using it to access mdb file like 5mb not 3GB :) from time to time. I'm going to use this thread to ask another question - I have two pfsense boxes IPSec site-to-site and it's working ok - 192.168.1.0 and 192.168.2.0. I'm connecting OpenVPN Mobile Client(192.168.3.0) to site 1 (192.168.1.0) and it's working ok too. Can i route somehow site2 (192.168.2.0) to access OpenVPN client ?

  • [ipsec] LAN, OPT1, and OPT2 -> cisco pix

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • PfSense IPSec on Dual-WAN setup. How to forward IPSec?

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • IPSec between Netscreen 5GT and pfsense 1.2.3

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    C

    @beaven67:

    If the Netscreen is the side with the dynamic address you will need to setup the vpn similiar to a Road Warrior type of VPN.

    Not with 1.2.3 and newer, just need a dynamic DNS name.

  • Unable to communicate both ways on active IPSEC VPN

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    Z

    I had this problem as well. I had oppened port 500 on the remote firewall, but had not oppened port 500 on my firewall for the return encrypted connection.

    Hope this helps,
    -=Zapped=-

  • G2G VPN - Ping works, nothing else.

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • 2 Subnets on one side of tunnel

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    J

    Right after I posted yesterday I thought I would try using the same PSKs, so far they have both stayed up for about 18 hours, so it is looking like that fixed it. Thanks!

  • IPSEC VPN via Public ip addressing/NAT overlap? anyone Beuler?

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    jimpJ

    Unfortunately, FreeBSD (and thus pfSense) can't combine NAT and IPsec (yet?).

  • Setting up pfSense for 'Road Warriors' via IPSec

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Disable filtering/scrubbing through VPN - How?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S

    Gave up on trying to do this. Instead created tunnel interfaces on the ciscos and am letting MPLS failover to GRE tunnels. Working surprising well. Doing port forwarding for GRE for the IP of hte router. Wanted to keep all the router IPs behind the firewall.

  • Packets to remote subnet not going through IPsec

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    T

    Gah, thanks for the clue-bat!

  • 0 Votes
    1 Posts
    2k Views
    No one has replied
  • IPSEC Only

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    In order for a VPN router like that to work, it would either need to be the gateway for all of the systems behind it, or you'd need a static route to your remote VPN client subnet on every server (or their gateway) that would point traffic at the VPN router.

    So it could work, but it takes a bit more effort to get it going.

  • IPSEC Between pfSense and FreeBSD 7

    Locked
    12
    0 Votes
    12 Posts
    10k Views
    S

    @dapriv:

    You can't just add a static route to the router?

    Nope.  This is a colo setup, so no, we don't have access to the router.  Just another line to stash in our default rc.conf…

  • Problem with tunnel between Sonicwall tz170 <> Pfsense

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    S

    @egarcia:

    I'm trying to replace actual TZ170 with pfSense appliance.
    Actually I have a IPSec tunnel between offices using two TZ170 firewalls.

    I did something similar, and it was actually the easyest ipsec I ever setup.
    (but, funny thing, and I'll post later on this) as soon as I ENABLE IPSEC on the pfsense, the access from the LAN to the BRIDGED DMZ stops, completely.

  • Wish to put together some ideas..

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    jimpJ

    Sure you can. You'd just need a static route on the OpenVPN router that directs traffic for the IPsec subnets at the IPsec router, and a static route on the IPsec router that points traffic for the OpenVPN subnet back at the OpenVPN router.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.