• 0 Votes
    2 Posts
    509 Views
    patient0P
    @dcugy I would update to the latest CE 2.8.0-RELEASE and report it when it happens again.
  • IPSec connections breaking or wireguard

    5
    3
    0 Votes
    5 Posts
    5k Views
    O
    wanted to see if i could try pfsense+ edition which used to be free but for some reason i can't seem to find that key, isn't it free for home users anymore?
  • 0 Votes
    1 Posts
    2k Views
    No one has replied
  • VPN to Mexico

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Modify IPSec auto generate key button

    1
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • (How TO) Deploying IKEv2 with EAP-MSCHAPv2 in Domain with group policy

    3
    0 Votes
    3 Posts
    10k Views
    I
    For some reason this is not working under Windows 11 24H2. I assume it has something to do with local access rights since I am also not able to copy the file via explorer directly from the network share to C:\ProgramData\Microsoft\Network\Connections\Pbk (as local admin without elevated rights). When I first copy the file to Downloads, then I am able to copy it in a second step to C:\ProgramData\Microsoft\Network\Connections\Pbk. Any ideas? Indiana Horschd
  • Route all subnet traffic over specific IPSec tunnel

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • IPsec performance inconsistent and slow

    3
    2
    0 Votes
    3 Posts
    3k Views
    T
    @tinfoilmatt thanks. The iperf3 tests are done on hosts, not on the firewalls directly. Interestingly, I've since also set up a WireGuard VPN and that seems to work a little better than IPsec, but still 20-30% slower with large file transfers over FTP than going over the WAN. Following the guide on Netgate's website for WireGuard, I noticed that they clamp down the packet size by adjusting the MTU rather than the MSS, I don't know if there's a reason for doing it like that. But as I'm seeing the WireGuard performance still a bit off, maybe it's not just an IPsec thing? I did wonder if the CPU was the bottleneck, but they never go above 20% or so usage so I doubt it's the processor that's the bottleneck.
  • vti IPsec, gateway not adding static routes on 24.11

    7
    1
    0 Votes
    7 Posts
    1k Views
    L
    OK, this has been working correctly for a couple months, but a few days ago the interface "lost" the IP address. The router hasn't restarted nor I can find anything in the logs. Had to reassing an IP address and it just continued to work. I will try to dig deeper in the gateway address handling to see if I find the bug.
  • Mobile Clients loosing connectivity akter 60 minutes

    5
    0 Votes
    5 Posts
    3k Views
    A
    I have run into the same issue a while ago. As others have mentioned, it is due to Windows using DH group 2 (1024 bit) at re-key time, even if it the P1 and P2 are configured with a stronger DH group. Changing the re-key interval to something like 9 hours is the easiest way to minimize disruption. Other options are to create the client connections using PowerShell to specify a higher DH group, or use DH group 2 on the server. https://learn.microsoft.com/en-us/powershell/module/vpnclient/set-vpnconnectionipsecconfiguration?view=windowsserver2025-ps
  • IPsec tunnels show as down, but they are working

    1
    4
    0 Votes
    1 Posts
    994 Views
    No one has replied
  • P2s flip-flopping and going stale

    2
    0 Votes
    2 Posts
    1k Views
    YayPeacePeaceY
    @TitaniumCoder477 Send a print of Status / IPsec / SADs and SPDs while the GEN_VLAN gateway is unreachable.
  • IPSec narrowing down

    1
    0 Votes
    1 Posts
    718 Views
    No one has replied
  • IPsec Site-to-Site VTI Only One Way Traffic

    3
    6
    0 Votes
    3 Posts
    872 Views
    LaxarusL
    Okay, after a long troubleshooting session. Problem is solved. For reference, I needed to recreate the firewall rules on both sites for ipsec, reload filters and reset states. I suspect it was a weird gimmick messing up the filters.
  • IPSec problem with one-way traffic flow

    8
    1
    0 Votes
    8 Posts
    2k Views
    C
    @viragomann @tinfoilmatt Based on your feedback I read up on asymmetric routing and ended up skipping pfSense for this setup altogether I always try to standardize on products but here it just lead to a level of network knowledge I do not fully understand. I configured a basic IKEv1 tunnel in the edge gateway, added necessary firewall rules and everything worked as intended. A sidenote is that IKEv2 did not work well in VMware NSX-V with the P2's being disconnected after 3600 seconds and not being able to reconnect without tearing down the P1 manually as well. [image: 1745913956839-ef365c84-1553-4c71-8c60-fbb1827af9a7-image.png] Thanks everyone for your input!
  • Routing Specific Traffic over VTI

    9
    2
    0 Votes
    9 Posts
    2k Views
    V
    @stan-fergusonsmith Does your application really use a static source port?? That's very unusual. Most application use a random source port. So you probably have to set the source port to 'any' in the port forwarding and firewall rule.
  • Routing ipv6 across tunnel

    1
    0 Votes
    1 Posts
    336 Views
    No one has replied
  • IKEv2 Policy Match Error on Windows 10 Client

    7
    0 Votes
    7 Posts
    6k Views
    S
    I know this is an old topic but I got here from searching the error message. In our case the person adding the VPN didn't use the .ps1 file from pfSense to do it, and Windows 11 24H2 still apparently uses weak algos by default.
  • IPsec site to site dropping every 49-55 minutes

    44
    0 Votes
    44 Posts
    9k Views
    T
    @michmoor I would love to give your reply a thumbs up, but apparently you have to have 5 something, and no clue on how to get that. Anyway, I'm going to look at wireguard; however, i upped my p1 timeout, rekey, and expiry times to 7 days then 10 under for rekey and 2 under for expiry and i've gone ahead and upped the p2 to 1 day and rekey at 5 minutes under. That was at 13:44 and we are now at 16:17 and we haven't had a drop yet.
  • IPSec to USG behind NAT

    2
    1
    0 Votes
    2 Posts
    538 Views
    M
    @tompark said in IPSec to USG behind NAT: It looks to be as if the connection between the USG and the PFSense I am connecting too, timesout. Is there a way that I can easierly check the traffic is being forwarded by the PFSense firewall? You can check pftop to see the state table. Doc is here
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.