• pfSense ipsec as default gateway to AWS VPC

    1
    0 Votes
    1 Posts
    400 Views
    No one has replied
  • IPSEC - Will creating more phase two tunnels slow down the VPN

    4
    0 Votes
    4 Posts
    803 Views
    R
    @daboomer without knowing how much data, the type of CPU, internet connection, other side CPU, internet connection, consistency of data, etc... The only thing we can say is it will increase CPU load. I consistently push 25Mbps to a datacenter over fiber about 6 miles away... but adding more P2s doesn't change my throughput at all on my 5100 on 1GbE
  • IPSEC VPN S2S one way communication

    1
    0 Votes
    1 Posts
    276 Views
    No one has replied
  • IPsec stopped routing to remote network after upgrade to version 2.6

    2
    4 Votes
    2 Posts
    649 Views
    T
    @rodfcabral same here - been met with silence from pfsense
  • ipsec client to site

    3
    0 Votes
    3 Posts
    689 Views
    I
    @viragomann I'm going to test, if there was an working ipsec client to client in the mikrotik, is that seems a good initiatives. thanks a lot
  • Double NAT outbound over IPSec

    2
    0 Votes
    2 Posts
    619 Views
    V
    @fifty_bellies You can do this by entering the desired translation network in the phase 2 at "NAT/BINAT translation". However, consider that on the remote site you have also to replace the remote network with the NAT network.
  • IPSec keyingtries setting

    8
    0 Votes
    8 Posts
    2k Views
    M
    @jimp Thanks for your input! I just activated this option and see if it resolves the issue. Is it best to activate it only on the initiating pfsense or on both sites?
  • IKEv2 "RW-equivalent" S2S

    1
    0 Votes
    1 Posts
    406 Views
    No one has replied
  • 0 Votes
    1 Posts
    427 Views
    No one has replied
  • 0 Votes
    2 Posts
    1k Views
    R
    Well according to this documentation NHRP via FRR is not available for FreeBSD. http://docs.frrouting.org/en/latest/overview.html#feature-matrix
  • MTU through IPSEC Tunnel for UDP Traffic

    2
    0 Votes
    2 Posts
    677 Views
    R
    Can anyone shed some light on this?
  • IPsec IKEv2 for mobile clients : NO_PROPOSAL_CHOSEN

    1
    0 Votes
    1 Posts
    436 Views
    No one has replied
  • IPSec firewall rules not added?

    2
    2 Votes
    2 Posts
    744 Views
    L
    I'm experiencing exactly the same issue
  • IPsec problems after 2.6.0 upgrade

    1
    0 Votes
    1 Posts
    567 Views
    No one has replied
  • IPsec VTI does not pass traffic on 2.6.0

    28
    0 Votes
    28 Posts
    3k Views
    jimpJ
    @thatsysadmin said in IPsec VTI does not pass traffic on 2.6.0: But why would having one of the phase 2s disabled break the whole thing though; shouldn't it be disregarded if it was disabled? It could probably handle that better, but it's not a valid combination to have a mix of tunnel and VTI even if some are disabled. They should all be the same type, and really there should be at most one VTI P2 per address family (so one IPv4, one IPv6). I'm not sure if we have validation which actively checks for and prevents that yet, though.
  • IKEv2 multiple phase 2 - negotiations for one network only

    5
    0 Votes
    5 Posts
    863 Views
    P
    It was a problem of sharing multiple destination networks in one child configuration (at pfSense side). Activation of 'Split connections' option seems to solve my problem. As I manage manually the configuration files at server side, it is more simple for me to have separate children (one child per network). Thanks for the assistance!
  • IKEv2 EAP-TLS Split DNS Not working on Apple iOS

    1
    0 Votes
    1 Posts
    381 Views
    No one has replied
  • IKEv2 IPSEC VPN - Randomly stopped working

    25
    0 Votes
    25 Posts
    4k Views
    B
    I added/changed it to AES/SHA256/DH14 in my router and client settings and rekey works! Way better than SHA1/DH2. I can live with this..
  • DDNS Hostname on remote gateway for IPSEC

    2
    0 Votes
    2 Posts
    505 Views
    werterW
    Hi there @lmendoza Godaddy https://sysadms.de/2018/09/godaddy-api-fuer-dynamischen-dns-eintrag-unter-pfsense-einrichten/ And you can get valid wildcard certificates (LE) with godaddy's dns api https://sysadms.de/2019/03/lets-encrypt-zertifikate-unter-pfsense-dns-godaddy/ Dynu.com (also you can get valid wildcard certificates (LE) with dynu dns api) https://www.dynu.com/DynamicDNS/IPUpdateClient/PFSense https://www.dynu.com/en-US/Forum/ViewTopic/How-to-create-subdomain/7065 https://community.letsencrypt.org/t/failed-authorization-procedure-the-server-could-not-connect-to-the-client-to-verify-the-domain/60656/4
  • IPSEC site to site VPNs do not work after upgrade to PFsense 5

    14
    0 Votes
    14 Posts
    3k Views
    N8LBVN
    This eventually got fixed over here: https://forum.netgate.com/topic/162012/pfsense-release-2-5-openvpn-2-5-broken-any-fixes/74?_=1644012845727
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.