• IPSec Firewall not allowing SNMP

    ipsec ipsec rules snmp
    1
    0 Votes
    1 Posts
    596 Views
    No one has replied
  • Ipsec Configuration not Working!

    66
    0 Votes
    66 Posts
    17k Views
    G
    @gary-lopez viva la raza carnal!
  • IPSec Site to Multi-Site VPN (Established but cannot ping local hosts)

    1
    1 Votes
    1 Posts
    358 Views
    No one has replied
  • Question about Site to site

    1
    0 Votes
    1 Posts
    344 Views
    No one has replied
  • Pfsense IPSEC LAN to LAN VPN: low bitrate output by iperf2

    2
    0 Votes
    2 Posts
    515 Views
    M
    Anyone already experienced and solved this issue? Additional info: both the pfsense instances are running on two VMware ESXi virtual machines (each one has 4 cores + 4GB RAM) Mauro
  • Restrictions on IPSEC clients

    3
    0 Votes
    3 Posts
    604 Views
    C
    @steveits said in Restrictions on IPSEC clients: https://docs.netgate.com/pfsense/en/latest/firewall/time-based-rules.html Thanks, I did try to create some scheduled firewall rules, but they don't seem to have any effect once a IPSEC connection is established. When blocking traffic, they stop the VPN connection from happening. But if the connection is already established, then the iPhone is still able to browse the internet through the VPN. I think this needs to be set up a specific way with firewall rules, but I don't know how to do that. It could also be that having pfSense in a VM makes a difference to how this is done.
  • IPSEC with Nat Translation - no route

    ipsec traslation routing
    2
    0 Votes
    2 Posts
    747 Views
    S
    @sdedurana a error in config. Solved. Please close.
  • Problem with connectivity outside of IPSEC when member is down.

    1
    0 Votes
    1 Posts
    320 Views
    No one has replied
  • Traffic not Routed Properly when i use Pfsense Lan IP

    1
    0 Votes
    1 Posts
    338 Views
    No one has replied
  • Can't connect IPSec if other IPSec connected

    1
    0 Votes
    1 Posts
    357 Views
    No one has replied
  • Mobile client failing to connect

    1
    0 Votes
    1 Posts
    392 Views
    No one has replied
  • IPsec tunnels not connecting during CARP HA failover

    carp ipsec
    3
    0 Votes
    3 Posts
    1k Views
    T
    Wanted to add a bit more info here as this issue remains even after upgrading to 2.6.0 today. My tunnels are IKEv2 in VTI mode. Under Phase 1 Advanced Options, I set "Child SA Start Action" to "Initiate at start (VTI or Tunnel Mode)" and "Child SA Close Action" to "Restart/Reconnect" Under Phase 2 > Keep Alive, I use a host on the other side of the tunnel with Keep Alive "Enable periodic keep alive check". The tunnels do not establish if I shut down the MASTER CARP node or "Enter Persistent CARP Maintenance Mode" on the MASTER CARP node. I have to click Connect to manually establish the tunnels. Seeing these messages in the IPsec System Log charon[43289]: 04[CFG] trap not found, unable to acquire reqid 5002 Have anyone else seen this issue?
  • IPSec status page not reflecting configured tunnels

    1
    0 Votes
    1 Posts
    353 Views
    No one has replied
  • IPsec Export: Apple Profile tilt?

    8
    0 Votes
    8 Posts
    980 Views
    NogBadTheBadN
    @ralph-1 Have you tried adding the VPN connection by hand on the Mac? I think the issue is with the profile including a self signed cert, at least it was with my iPhone. Down load and trust the CA and the additional cert first then add the connection by hand.
  • Two way IPsec tunnel with single interface is doable?

    1
    0 Votes
    1 Posts
    284 Views
    No one has replied
  • IPSEC Hub to spoke VTI issue/limitation.

    1
    0 Votes
    1 Posts
    391 Views
    No one has replied
  • Mobile Client / Windows 10 / Disconnects every 57min / No error

    1
    0 Votes
    1 Posts
    297 Views
    No one has replied
  • Why IPSec tunnels with VTI effects each other?

    3
    0 Votes
    3 Posts
    634 Views
    G
    Actually I stand corrected. In the advanced setting for the Phase 1, there is a setting to allow multiple P1s. Gateway Duplicates Allows multiple phase 1 configurations to use the same remote endpoint address. Warning This option also disables automatic static routes to the peer via specific WAN gateways. Traffic will follow the default route, not the selected tunnel interface, unless manual static routes redirect the traffic. You'd need to have that option enabled and set up static routes.
  • IPSEC Phase 2 Configuration

    1
    0 Votes
    1 Posts
    521 Views
    No one has replied
  • After configure some IPSEC tunnels PfSense collapse

    ipsec webgui freeze vpn tunnel
    2
    0 Votes
    2 Posts
    762 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.