• Need help with IPSEC-IPSEC-Wireguard setup

    2
    0 Votes
    2 Posts
    598 Views
    F
    @frika issue resolved. In order for the outside routed to gain access I had to extend the subnet of the Ubuntu server-2 (ubuntu server-2 and mikrotik have to be within the same range/subnet).
  • 0 Votes
    4 Posts
    660 Views
    G
    @gassyantelope Our issues was on any add or change to an IPSEC configuration. The Status, IPSEC page was very slow as well, up to a minute to load. Now loads in <1 sec. 2.6.0 definitely fixed all our IPSEC setup and modify 504 errors.
  • IPSec tunnel ping initialization

    3
    0 Votes
    3 Posts
    855 Views
    M
    @jok said in IPSec tunnel ping initialization: Hello. I have set up a tunnel between two sites. The tunnel establishes connection perfectly. But I obtain a strange behaviour: If I ping from a PC1 from site A to a PC2 in site B, the ping not respond. If I ping inmediatly from the PC2 from site B to the PC1 in site A, both pings start working. The same with all the computers. Some ideas? Thanks! Hi! What rules? I have the same exact problem
  • ipsec vpn bug found

    2
    0 Votes
    2 Posts
    1k Views
    N
    https://redmine.pfsense.org/issues/12645
  • IPsec invalid payload

    5
    0 Votes
    5 Posts
    1k Views
    L
    @konstanti These are the rules. I'm using port 1600 for the GUI. Is there anything wrong? In IPsec I have added the VPN network of 10.3.200.0/24 [image: 1654013921185-ipsecrule.png] [image: 1654013928383-fwrules.png]
  • IPSEC on iPhone using pfSense - connects but no access

    2
    0 Votes
    2 Posts
    584 Views
    keyserK
    @amrogers3 Yes, I have IPSec working just fine with Windows 7 -> 10, MacOS, iPhone and Android phones all on the same Mobile IPsec setup on a pfSense. Mind you though - i believe I remeber there were some issues that you had to be very carefull about on 2.4.5 because it was less than capable of supporting the lastest standards. I would strongly recommend you upgrade to 2.6 and implement your IPsec as a IKEv2 setup. Works beautifully with all the clients, and the only major drawback is in enterprise size networks because Netgate has not implemented named IP pools to assign clients to with Radius returned class info. So all clients are treated the same because you cant separate them by IP unless you create static IP return rules pr. User from radius.
  • Virtual Address Pool in Pre-Shared Keys is not used for IPSec

    8
    0 Votes
    8 Posts
    2k Views
    keyserK
    @keyser Just bumping this thread out of Interest. Does anyone know if making IPsec Road warrior “usable” in larger corporations is actually on the roadmap from Netgate, or will it just be stranded at “one pool, one ruleset for all VPN users” going forward? The Framed-IP-Address is not a solution in larger networks due to the massive maintenance issues it brings.
  • IPSec Phase1 DynamicDNS still not working in v2.6

    2
    0 Votes
    2 Posts
    756 Views
    B
    @vicedriver i have the same issue on 2.6 dynamic dns client, is not updating no-ip record and the vpn clients cannot connect. The workaround is i have configure this pfsense as vpn client, so it can connect to my static ip pfsense and gain routing to itts interface. After that, i press the button save & force update to renew. [image: 1653308046424-faf4bf3a-259d-44ea-a93e-145e35feb95f-image.png]
  • IPSec doesn't reconnect?

    1
    0 Votes
    1 Posts
    447 Views
    No one has replied
  • two-tunnels routed ipsec reverse traffic issue

    2
    0 Votes
    2 Posts
    562 Views
    J
    Appeared to be a states clearing issue. Please, disregard
  • IPSEC with PPPoE: error writing to socket: Can't assign requested address

    1
    0 Votes
    1 Posts
    703 Views
    No one has replied
  • IPsec hub with 16 spokes supernet

    ipsec hub & spoke s2s access
    1
    0 Votes
    1 Posts
    629 Views
    No one has replied
  • Can't pass traffic using VTI if_sec if destination was powered off

    1
    0 Votes
    1 Posts
    506 Views
    No one has replied
  • PF_KEY buffer overflow errors - killing ipsec tunnel

    2
    0 Votes
    2 Posts
    779 Views
    jimpJ
    Upgrade to a more recent supported release. That was fixed a long time ago.
  • 0 Votes
    2 Posts
    1k Views
    M
    I want to make tunneel between pfsense and vps, I have no idea how to do that. Kindly help
  • Remote Id for VPN site to site

    2
    0 Votes
    2 Posts
    1k Views
    I
    @ivan0 Any support about the request above?
  • Is VTI currently broken?

    1
    0 Votes
    1 Posts
    645 Views
    No one has replied
  • IPSec Routing is not working after upgrading pfsense from 2.4.4 to 2.6.0

    2
    0 Votes
    2 Posts
    858 Views
    T
    Hello Team, Can you please help us on above issue? Thank You
  • IPSEC VPN connects from iOS, but does not route traffic

    4
    0 Votes
    4 Posts
    2k Views
    D
    We've enountered a lot of Issues with VPN on iOS devices. A core-point is Apple's DNS-Privacy: When connected to a wifi, apple by default is ignoring the assigned dns servers (and therefore any dns assigned by the tunnel) and instead is using the apple cloud dns, "to protect your privacy" (at least that's the reason they claim) You can set the dns-server for a particular wifi to manual to resolve this. Just becomes very unhandy, if you have hundrets of clients dealing with that "feature". Your observation about the IPV6 / IPV4 difference might be the problem: Your iPhones provider is using IPV6, and your ipv4-connection is then only an ipv4 over ipv6 tunnel (In our country referred to as "Dual-Stack-Lite / DS-Lite"). Here you'll have limits on the usable ports - depending on the provider. He might have decided, that a common user needs to use port 80 and 443, therefore created the proper rules for that, but everything else well not be forwarded. (Your Phone would be the router here, IPV4 only over nat'd IPV6) [image: 1651479875878-8ac39221-c653-4377-8ab2-11c2e88ca251-image.png] Your best option here would be to make your vpn-server ipv6 capable , OR (that's what we did): Use Port 143 - that's IMAPS - nobody is using imap nowadays, but that port is most likely served by your isp.
  • Can you setup an address pool for IPSec clients ?

    2
    0 Votes
    2 Posts
    795 Views
    NogBadTheBadN
    @paul1923 Freeradius and framed-ip addresses will enable you to do this per user. https://forum.netgate.com/topic/115795/guide-ikev2-ipsec-per-user-firewall-rule-settings-with-freeradius
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.