• Tunnel accessible one way

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    H
    Add a firewall rule like this at the loadbalancing pfSense (top of the firewallrules): pass, protocol any, source lan subnet, destination network 10.0.0.0/24, gateway default This will fix it.
  • Multiple machines VPN to same endpoint with VPN Client through pf

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    P
    I found a solution to my problem, I do not think it is a good solution but it works good for the moment. on the pfsense (1.0.1) I just activated the "Enable advanced outbound NAT".
  • LAN TO LAN WITH 4 VPN TUNNEL (REDUNDANT)

    Locked
    28
    0 Votes
    28 Posts
    20k Views
    M
    Thear hoba: Plz need help, cant resolve this problem.I will become crazy My config is the next. LAN       |   (PfSense 1)   |              | ISP1 (WAN)    ISP2 (OPT-WAN)   |              |   |              | (  Internet )       |          |          ISP3       |          |        pfSense2 (waiting for mobile clients)       |       LAN Both pfsense have static ip. pfsense-1 have load-balancer & squid The tunnel is stablish with ISP1 and ISP3 using in pfsense3 mobile clients. At less ISP1 is down then Switch to ISP2 The nexts problem happend when ISP1 is down: A) I change manually the IPSEC VPN Start Point to ISP2, (Now Tunnel is between ISP2 and                ISP), but not connection is stablish at less add the next static route :                        <opt1>      <destination 32="" end="" point="">      <opt1-gw>B) PFSENSE Can't resolve DNS at less add the next statis route:                       <opt1>      <destination 32="" dns="" server="">      <opt1-gw>C) Squid (Running in pfsense 1) don't work any form. Problems A & B resolve with staric route, C can't but when ISP1 is up again, i need change again the IPSEC VPN Start Point (because isp1 is better)  and delete all static route. The really problem is write and delete a static continuously with time I criticize of production that this uses. My Idea is only change the ISP START POINT MANUALLY (ONLY CHANGE COMBO IN IPS-VPN) and all work fine. It is there possible? Is not, know u other solution. Any solution for squid when WAN is DOWN?</opt1-gw></destination></opt1></opt1-gw></destination></opt1>
  • IPSEC to CARP cluster

    Locked
    7
    0 Votes
    7 Posts
    5k Views
    S
    @morbus: I tested the failover yesterday and it all worked fine except that the CARP copying (XML-RPC I guess) didnt copy the 'Failover IPSEC IP' to the slave so the slave was trying to use its own IP and the remote end was using the CARP one. I just had to fill in the 'Failover IPSEC IP' on the slave and it worked fine Yep.  Sorry, I forgot that step.  Glad that it is working now.
  • PfSense to FreeBSD VPN/IPsec

    Locked
    15
    0 Votes
    15 Posts
    8k Views
    K
    @J.Borg: @hoba: Guess because it's a gif/ipsec tunnel? You can run it with one tunnel like 192.168.200.0/24 <-> 192.168.0.0/16. Ask the admin of the other box to change his tunneldefinition this way and change it at your end and you should be fine. Thank you, after I edited spdadd as per your advice things start to look better now (have not edited gif on FreeBSD client 1 side however). I can reach Client 2 phone system. Some more work is needed… dear all I want to make connection between pfSense and FreeBSD 6.2RC vis IPSec But no works. could any one establish successfully?
  • Connecting to Remote (Dynamic IP Address) Gateway

    Locked
    6
    0 Votes
    6 Posts
    6k Views
    L
    I am using OpenVPN for now because I have two DHCP endpoints.
  • Pfsense monowall and IPSEC

    Locked
    13
    0 Votes
    13 Posts
    11k Views
    H
    @moffl: for your info. Don't know what i am missing Tried it no go. just set up a ipsec tunnel on 2 different computers over a completely different network and it is responding exactly the same can't receive email, can not download files, cannot remote. it may be my imagineation running away right now but it seems when you first start email program or download their is the first initial indtall then stops hope this helps Are you sure routing is setup correctly back and forth? Besides that it somehow sounds like a mtu issue. Lower mtu's at both WANs (m0n0 and pfSense) to 1300. If that helps raise the values step by step until it breaks again and go back one step. I had a m0n0-pfSense tunnel from work to home for several month and was able to use my outlook at home connecting to the exchange server at the office without issues. Oh, wait… "Routes are in place"??? You don't need static routes. Only setup the tunnels. The routing is determined by the local and remote LAN of the tunneldefinition.
  • Why pfSense doesn't support larger DH groups?

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    S
    It is my understanding that we support everything that the freebsd kernel + racoon supports.  Feel free to supply diff's in unified format if this is not the case.
  • Netopia 3381-ENT to Pfsense 1.0.1

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H
    I have not seen a netopia vpn configuration screen yet but if you paste some screenshots I might be able to help you. Some vendors call some options different or break up the oprions into several screens that reference each other. Also logs of a connectionattempt could be useful.
  • Exchange type 6

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    M
    Yepp I got the same problem and have anyone any clue to solve it??? Greetings, Marcel
  • Failover IPSec - sasyncd.conf is missing

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    B
    i can see it on my keyboard, so I use them :-)
  • Invalid agument

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    D
    What happens if you increase the PFS key group setting to 2 on the second layer. I had this problem also, renewed the setup several times and now its gone (now using ESP-3DES-SHA1-PFS Key 2).
  • Two VPN with dual wan

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    S
    pfSense has openvpn.  I would imagine this would work fine with the push routes features?  Not sure, I don't even run OpenVPN but don't see why it wouldn't work.
  • IPSEC connected but cannot ping remote network.

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    S
    Personally I would give OpenVPN a try over PPTP.
  • Can't enable my ipsec tunne

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • IPSec endpoint at LAN

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • IPSec VPN with Cisco PIX

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Can iVPN be use in Roadwarrior?

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    L
    I would like to know that as well. My clients are using sim/smartcards to store an identifier and I'm wondering if I can read from those sims some sort of a key rather than a cert.
  • IPSec for RoadWarriors on Windows using SIM/Smartcards?

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Upstream Squid Proxy via IPSEC

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    X
    I was able to work around this by creating a port forward nat rule on the lan interface with the ip as ANY with the external port as http and internal ip/port as 192.168.0.12:8080 then i disabled the local squid proxy.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.