• Odd IPSeC Situation - Can't Figure It Out

    1
    0 Votes
    1 Posts
    196 Views
    No one has replied
  • slow transfer speeds ove ipsec

    39
    0 Votes
    39 Posts
    4k Views
    planedropP
    @hescominsoon Glad it's working better now. SMB will definitely be slower but should be far more usable.
  • DNS override only when IPsec tunnel is up

    1
    0 Votes
    1 Posts
    225 Views
    No one has replied
  • 0 Votes
    1 Posts
    165 Views
    No one has replied
  • IPsec tunnels (new to this)

    2
    0 Votes
    2 Posts
    291 Views
    V
    @RET63 If pfSense is behind a router you have probably to update the identifier on both sites. If you have changed the ISP router also remember to configure the port forwarding on it.
  • IPsec Tunnel Woes

    3
    0 Votes
    3 Posts
    383 Views
    V
    @pharceface You want to access the remote site from pfSense itself or access a service on pfSense from remote? Then you'll need a Static Route Workaround as explained in the docs.
  • 0 Votes
    17 Posts
    2k Views
    G
    @michmoor said in More than one IPSec tunnel phase1 is fine, but adding another phase1 prevents an existing tunnel from re-establishing a connection: @jimp nice. i have been following this out of curiosity. I have been a bit worried about the stability of IPsec on the platform based on my current experience so this has been an interesting post to follow. I would've never thought about the remote id being a problem. Makes sense Indeed an interesting finding and definitely something to investigate to see if it resolves my issue...
  • 0 Votes
    2 Posts
    193 Views
    lifeboyL
    Sorry, I didn't realise this will create a new thread. Can an admin deleted this please?
  • IPSEC Tunnel traffic only works one way

    3
    0 Votes
    3 Posts
    523 Views
    B
    @viragomann Thanks! Your reply helped me understand the flow which I was trying to do from the IPSEC and WAN Rules. Kept the WAN Rules simple and fixed IPSEC Rules and added LAN rule. Works now! Thank you for a quick educational lesson!!
  • ipsec not finding peer config

    4
    0 Votes
    4 Posts
    933 Views
    E
    @viragomann thank you very much it now works. It was set as "My IP Address" but seems that it don't work when it is not explicitly set.
  • 0 Votes
    2 Posts
    675 Views
    L
    that setting on server side is not necessary. once we setup the radius server correctly the X509 error messages were gone.
  • 0 Votes
    4 Posts
    538 Views
    lifeboyL
    @Gblenn This is strange. I previously simply added a new tunnel and it works. It's been a while since I last did this, maybe about 6 months, and now suddenly this strange behaviour happens.
  • IPSEC autoconnection - Manual?

    3
    0 Votes
    3 Posts
    332 Views
    perikoP
    @jimp Thanks master, I will.
  • Traffic tunnel to tunnel

    2
    0 Votes
    2 Posts
    246 Views
    V
    @andmattia You need also to add a phase 2 on the Cloud -> MyCustomer IPSEC with 172.172.2.0/24 - 192.168.X.X. BTW: Why are you using public network ranges inside your LAN??
  • iOS 18.1 can't establish connection anymore

    5
    2
    0 Votes
    5 Posts
    616 Views
    tinfoilmattT
    Correction to my previous post: the working iOS 18.1.1 device actually does NOT have LE's CA cert manually imported. (LE is apparently now a trusted a root authority in iOS.) The VPN configuration profile itself is self-signed however—and it's that signer's CA cert that's manually installed on this working device. Doubtful that any of this is relevant. Just wanting to clarify. Apologies for any confusion.
  • Allow only certain IPs to connect to home pfSense?

    7
    0 Votes
    7 Posts
    895 Views
    T
    @SteveITS Thanks Steve. I did not Disable Auto-added VPN rules. The block ports 500 and 4500 rules I added are being hit and the logs have been quiet, so looks like being at the bottom of the WAN list is okay.
  • Authentication methods not available as documented?

    6
    0 Votes
    6 Posts
    560 Views
    jimpJ
    There can be only one mobile P1 at a time. You can either remove the old one and create a new one, or change the settings on the old one to match what you want it to be now.
  • snmp over ipsec

    6
    0 Votes
    6 Posts
    589 Views
    G
    @reynold Actually you install Avahi as a package on pfsense, not on the windows clients.
  • IPSEC > Routing traffic from A Site to C Site through B site

    5
    0 Votes
    5 Posts
    554 Views
    D
    @viragomann Hi! Thanks a lot, ill try and let you know the result Warm Regards
  • Switching IPsec from IPv4 to IPv6

    4
    2
    0 Votes
    4 Posts
    440 Views
    K
    @johnpoz Correct. CGNAT is being rolled out, so I’m trying to switch anything that might be affected to v6.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.