• USG Pro to NetGate 2100 VPN Tunnel Keeps Dropping

    1
    0 Votes
    1 Posts
    308 Views
    No one has replied
  • IPSEC BOVPN Timeout

    2
    0 Votes
    2 Posts
    401 Views
    jimpJ
    From that screenshot it appears you have disabled both rekey and reauthentication. So when the P1 expires (at most every 8 hours, likely about 1/2 to 2/3 that time) it can't renegotiate a new P1. The exact method to solve this depends on the tunnel configuration and what the other side supports. Generally speaking, however, you should have a positive value in either rekey or reauth time. See the recommendations for values here for a good guide: https://docs.netgate.com/pfsense/en/latest/troubleshooting/ipsec-duplicate-sa.html
  • IPSec missing autogenerated firewall rules over IPv6

    2
    0 Votes
    2 Posts
    448 Views
    L
    update 1 manually added rules for IPv6: isakmp, sae-urn, esp. now it works. but I guess this is still a bug
  • IPSEC multi subnet some work, others dont

    1
    0 Votes
    1 Posts
    274 Views
    No one has replied
  • Ping not working in Routed (VTI) interface

    vti ping
    3
    0 Votes
    3 Posts
    1k Views
    C
    Thanks for the suggestion but unfortunately no PING. Since I am able to ping 172.30.2.1 (but not 172.30.2.2), could it be something related to firewall or routing?
  • IPSec leases not showing

    4
    0 Votes
    4 Posts
    824 Views
    E
    Finally fixed it. Use Radius for authentication. When I checked the Radius server settings. I noticed that I made a config mistake I set the Services Offered to "authentication". When I changed it to "authentication and accounting". Everything started working as it supposed to.
  • Strongswan - increase retransmit_tries from default of 5

    1
    0 Votes
    1 Posts
    719 Views
    No one has replied
  • Tunneling between IPsec -> Traffic selector wrong

    1
    0 Votes
    1 Posts
    342 Views
    No one has replied
  • Multiple IPSEC Customers with the same LAN subnet

    3
    0 Votes
    3 Posts
    645 Views
    I
    @jimp Ok, thank you for the response. That does make sense to me as well but I wanted to check just in case. Thanks!
  • pfBlockerNG and IPsec blocked

    1
    0 Votes
    1 Posts
    323 Views
    No one has replied
  • IPSec on backup node

    1
    0 Votes
    1 Posts
    467 Views
    No one has replied
  • VPN IPSec/IKEV2 + Active Directory Auth + 2fA

    1
    1 Votes
    1 Posts
    921 Views
    No one has replied
  • IPSec Tunnels duplicating phase 2

    9
    0 Votes
    9 Posts
    1k Views
    M
    @jimp ive had an idea which i just tried. i made a subdomain for each phase 2 entry (4 in sum), so i connected 1 ipsec (phase 1) with the IP and added another 3 with different subdomains to the same ip and with the different phase 2 entrys. Seems to work. Looks pretty ugly but at least it works on 2.5.2. ugly ipsec
  • ECDSA certificate and IPSec

    1
    0 Votes
    1 Posts
    464 Views
    No one has replied
  • IPsec - connection failed

    1
    0 Votes
    1 Posts
    437 Views
    No one has replied
  • IpSec Bandwith

    2
    0 Votes
    2 Posts
    585 Views
    E
    Do you have Hardware crypto enabled?
  • IPsec preshared key question

    1
    0 Votes
    1 Posts
    375 Views
    No one has replied
  • One IPSec client failing to get `received packet` at certificate stage

    2
    0 Votes
    2 Posts
    535 Views
    S
    I think I've maybe found the issue. I think his home ISP is blocking something. If he creates a wifi hotspot on his smartphone, his Window PC can then connect to our VPN!
  • IPSec split tunneling

    2
    0 Votes
    2 Posts
    689 Views
    V
    @billyhart01 said in IPSec split tunneling: What am I doing wrong? If you tell us, what you did, maybe someone can answer this question.
  • One connection drops the other

    5
    0 Votes
    5 Posts
    1k Views
    E
    @dylanw Hi, did you find a solution for this? Because even with the new 2.6.0 beta I experience the same issue. Still staying on 2.5.1 for that reason. Thanks
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.