• Stable version with ipsec and load balance

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    Cry HavokC
    That's normal and if you search the forum you'll find many posts asking the same question  ;)
  • Problems connecting to watchguard soho 6

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    H
    Not all guis have all settings at one page. Some vendors prefer to have multiple pages for that and reference one of the settings from another screen. Other vendors hardcode some of the settings and you have to know what they have set them to on the other end. I have pfSense systems connected to several other products via ipsec. It's sometimes hard to find out how to configure them but in the end it always worked for me.
  • Ipsec interface in 1.2-RC1

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    S
    This was discussed yesterday.  Please search before blindly opening forum topics.
  • IPsec tunnel established, no traffic passsing through

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    H
    It must be at least natting which can cause problems as you have a private IP behind it.
  • Routing over ipsec

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • IPSEC passthrough problem

    Locked
    9
    0 Votes
    9 Posts
    6k Views
    D
    I can confirm that logging UDP traffic works now with Beta 2  ;D Will test the other problem soon. Greets Dave
  • IPSEC to Cisco VPN as backup

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    F
    We're new to pfsense, and just starting to test. What you're describing is possible. You would setup different weights for routes, and Cisco has a tracking feature that would ping an IP address. When the preferred route fails, you would alter the route weight and move the packets over the backup connection.
  • IPSEC makes pfSense reboot?

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    J
    We are still having this problem  :(, Not sure if anyone else can help us out but here's what the ASA5510 looks like: A.A.A.A = Remote LAN B.B.B.B = Remote public IP Y.Y.Y.Y = Local LAN Z.Z.Z.Z = Local public IP : ASA Version 7.0(5) ! interface Ethernet0/0 speed 100 duplex full nameif PUBLIC security-level 0 ip address Z.Z.Z.Z 255.255.255.0 ! interface Ethernet0/2 nameif PRIVATE security-level 100 ip address Y.Y.Y.Y 255.255.255.0 ! access-list PUBLIC_access_in extended permit ip A.A.A.A 255.255.255.0 Y.Y.Y.Y 255.255.255.0 access-list nonat extended permit ip Y.Y.Y.Y 255.255.255.0 A.A.A.A 255.255.255.0 access-list PUBLIC_cryptomap_20 extended permit ip Y.Y.Y.Y 255.255.255.0 A.A.A.A 255.255.255.0 crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac crypto map PUBLIC_map 20 match address PUBLIC_cryptomap_20 crypto map PUBLIC_map 20 set peer B.B.B.B crypto map PUBLIC_map 20 set transform-set ESP-3DES-MD5 crypto map PUBLIC_map interface PUBLIC isakmp identity address isakmp enable PUBLIC isakmp policy 10 authentication pre-share isakmp policy 10 encryption 3des isakmp policy 10 hash md5 isakmp policy 10 group 1 isakmp policy 10 lifetime 3600 tunnel-group B.B.B.B type ipsec-l2l tunnel-group B.B.B.B ipsec-attributes  pre-shared-key *  peer-id-validate nocheck tunnel-group-map default-group B.B.B.B no vpn-addr-assign dhcp no vpn-addr-assign local
  • IPsec tunnel stop working after upgrade to beta 2

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    B
    Its help, thanks Heiko… @heiko: Scott wrote on the mailing list: Try a snapshot later today or run this command and reboot: chmod a+rx /usr/local/bin/*.sh
  • How can I automatically release/renew an IPsec tunnel?

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    C
    i've been having same issues alot but after cmd and hoba suggested to check settings i found that lifetime on all routers if off. after adjustment everything works greate… but you gonna have to get settings from the other end of the tunnel to match them on your end.
  • IPSEC-VPN <-> openswan (Astaro) without chance

    Locked
    1
    0 Votes
    1 Posts
    7k Views
    No one has replied
  • Ipsec vpn shaping

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    B
    My question is not about shaping ipsec traffic.. but i think i found the answer: The original TOS field is copied to the encapsulating IP header, so the qos information still remains on the encrypted packet and can be routed/queued/prioritized accordingly. Regards, Reto
  • IPSec Debugging Tips

    Locked
    3
    0 Votes
    3 Posts
    8k Views
    M
    There is a racoon configuration directive called 'log info|debug|debug2'. I added it manually to /var/etc/racoon.conf, killed racoon and started it manually using /usr/local/sbin/racoon -f /var/etc/racoon.conf. Too bad there isn't a GUI option for it somewhere (or is there?) Anyway, more specifically, by setting it to debug2, I get this: Jun 29 17:30:58 racoon: DEBUG: 32953411 3a24b070 00000000 00000000 01100400 00000000 0000010c 04000038 00000001 00000001 0000002c 01010001 00000024 01010000 800b0001 800c7080 80010007 800e0100 80030001 80020002 80040002 0a000084 8239ea94 e4bf1ad1 3c9a02d3 6103ba0b 50b669b5 8ca55b22 79f90a6f 62d4f840 85632dcb cfa7e7c5 ea5601da 724aa79e 5a8b6997 15739a07 79330d88 948ffa4c 20a19ce6 442538f0 d0182aaa caf80d76 9c47049f 11cd3c72 471e475a c6d675bc ca4a1f7d b1271636 52c30de3 2ac6ea4c bc945bd3 e9683a82 fc5b0d0a 236f2ef8 05000014 99e5be30 5910045b b768c0a6 89ef8c57 0d00000c 011101f4 40936165 00000014 afcad713 68a1f1c9 6b8696fc 77570100 Jun 29 17:30:58 racoon: DEBUG: resend phase1 packet 329534113a24b070:0000000000000000 Jun 29 17:30:58 racoon: DEBUG: === Jun 29 17:30:58 racoon: DEBUG: 40 bytes message received from 62.x.y.z[500] to 64.a.b.c[500] Jun 29 17:30:58 racoon: DEBUG: 00000000 00000000 00000000 00000000 0b100500 f37b30ee 00000028 0000000c 00000000 0100001d Jun 29 17:30:58 racoon: ERROR: malformed cookie received. Any idea what might be causing the malformed cookie? – james
  • Site to site

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    S
    Okay now the sites are working.  ??? Now I`m going to try and add a adtran netvanta 2300,and a cisco 2600 into the mix. Looks like the adtran will not support blowfish encryption.
  • IPSec on OPT1

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    T
    @hoba: The static routes are still needed. Autocreation of this is a bit tricky currently. Maybe we'll implement this later (after 1.2 is out). Where do the static routes point to? other question: does it work with one PFsense box on the WAN IPSEC port/tunnel and one PFsense box on the OPT IPSEC port/tunnel?
  • Multiple wan, multiple mobile clients

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Is this pobible?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    U
    I answer myself. Is posible. The problem was the two diferents versions of pfsense. Cheers
  • IPSEC with especific Lan address but in diferent network of Lan

    Locked
    10
    0 Votes
    10 Posts
    4k Views
    J
    Hi, now I cam stablish a VPN with a Vlan on WAN interface but i cam only ping fron the pfsense itself. Any sugestion on how i cam make a route, nat or a rule from the LAN 192.168.0.0/24 to a VLAN 78.0.10.96/28.
  • IPSec with pfSense 1.2-BETA-1 on Soekris 4801 crash & reboot problem

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    R
    I've got some WRAP boards that are very similar to the Soekris 4801. 128MB RAM and 266 MHz. I had a problem with 3DES VPN rebooting them if I sustained VPN traffic for more that about 10 seconds if the other side was capable of handling more than about 4 mb/s. With a VPN1411 card in each, I sustained almost 9 mb/s with no reboots between 2 of them. This was not with the new beta version though. I haven't run it on an embedded platform yet. Here's the thread on my throughput testing. http://forum.pfsense.org/index.php/topic,1869.0.html
  • Filter reload error - "USER_RULE: Permit IPSEC traffic…"

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C
    What's the exact version you're running? Can you replicate it with the latest snapshot from http://snapshots.pfsense.org/FreeBSD6/RELENG_1_2/
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.