• I can ping both directions but only access servers one way...?

    18
    0 Votes
    18 Posts
    2k Views
    G
    @viragomann Well, since I couldn't get the default one to work, I tried VTI and it worked. Not sure what I did wrong with the other method but I did find VTI a bit more like the WG tunnels I have set up in the past. With the gateway and routing settings at least...
  • FTP su VPN IPSEC

    1
    0 Votes
    1 Posts
    193 Views
    No one has replied
  • 0 Votes
    8 Posts
    919 Views
    D
    @dnacom The next release would usually include the patch. You can either leave the patches installed and upgrade (will then still show the patch as installed in system patches) or revert the patches before upgrading and then upgrade as normal. Hope that makes sense
  • IKEv2 — невозможно подключить Android, iOS и macOS

    1
    0 Votes
    1 Posts
    145 Views
    No one has replied
  • android ipsec vpn: "connected. not secure"

    1
    0 Votes
    1 Posts
    178 Views
    No one has replied
  • IPSEC DHCP plugin

    3
    0 Votes
    3 Posts
    350 Views
    S
    @keyser Thank you for your reply! Yes, I need those options for split routing. The Windows VPN client is just capable of class based routing and ignores pushed routes. So per default it just adds a class based route to the remote net and ignores everything else except ip address. Here is an excerpt from the Strongswan documentation: Split Routing since Windows 10 Microsoft changed the Windows 10 VPN routing behavior for new VPN connections. Option "Use default gateway on remote network option" in the Advanced TCP/IP settings of the VPN connection is now disabled by default but can be enabled if desired. Fortunately Windows sends a DHCP request upon connection and add routes supplied in option 249 of the DHCP reply. Sample configuration file for dnsmasq: dhcp-vendorclass=set:msipsec,MSFT 5.0 dhcp-range=tag:msipsec,192.168.103.0,static dhcp-option=tag:msipsec,6 dhcp-option=tag:msipsec,249, 0.0.0.0/1,0.0.0.0, 128.0.0.0/1,0.0.0.0 where 192.168.103.0 is your (internal) network. It pushes two separate routes which cover the entire IPv4 range. Gateway could be anything (set to 0.0.0.0 in an example) as it is ignored by Windows. Note that you can’t ignore DHCP routes in Windows. Strongswan Documentation for Windows clients In my opinion this can only be achieved with the dhcp plugin. So for supporting Windows clients without configuring something manually, you need dhcp.
  • IPSec VPN Client and access to office server

    3
    0 Votes
    3 Posts
    338 Views
    Q
    @viragomann said in IPSec VPN Client and access to office server: The settings are wrong. You need to state local network: 192.168.109.0/24 remote: 192.168.89.0/24 Remember to configure the second p 2 on the remote site as well with exchanged networks. Many Thanks, this is good setting, now work both Phase 2 and VPN Client has access to server 192.168.173.0/24 and to Synology 192.168.173.0/24 site.
  • Users are being disconnected at a certain time

    4
    0 Votes
    4 Posts
    417 Views
    GertjanG
    @movIT You are probably limited by the GUI. You could go here : Status > System Logs > Settings and change [image: 1725431946352-c5dad0b9-bcbc-4136-8867-484d78c846fc-image.png] to something a bit bigger. Check also this : [image: 1725431976584-4280c79f-7433-4ea4-b1c1-6f317c100f08-image.png] where you can set overall log file size. If you have many G bytes to spare, you can make these files a bit bigger. On very small devices : be carefull. But you can also apply the "IT" way : you don't care about GUI ... go native access right away. Go to the source. Use the console, or, like everybody else, use the SSH access, and look her /var/log/ as that is the place where logs are stored on nearly every "computer" on planet earth. You'll find the system.log file. Btw : typically, I have 20-30 lines a day in the System log file. So "only the last 5 minutes worth" is pretty strange : what is happening in there that your pfSense logs that much ? ? Massive logs == normally : an indication something not-ok is going on.
  • Azure pfsense one way traffic

    1
    0 Votes
    1 Posts
    165 Views
    No one has replied
  • IPSEC port forwarding issue

    4
    0 Votes
    4 Posts
    433 Views
    V
    @netgate-powdered559 And the page works if you access it directly from the lab and from the internet if the latter is even possible?
  • IPSec is very slow between two pfsense routers

    40
    0 Votes
    40 Posts
    11k Views
    P
    @optimusprime I apply in this option: [image: 1724847936234-d15f6b0e-dc4f-4612-9973-a628ee43d373-image.png] [image: 1724847911969-8d1c5b5b-af44-4ef6-aa5f-1b5f3cfd3100-image.png]
  • Phase 2 Entries for IPSec Multi-Site Hub and Spoke

    2
    0 Votes
    2 Posts
    241 Views
    V
    @bkhiatt Are all phase 2 shown up as connected in Status > IPSec? Please post Status > IPsec > SPDs of all three sites.
  • MacOS VPN import

    5
    1 Votes
    5 Posts
    494 Views
    Sergei_ShablovskyS
    @SteveITS said in MacOS VPN import: Most of my Mac experience was on System 6/7. :) The double click started the import but didn't open anything. Ouch! Really ??? So welcome and try “the *nix with a human face”! ;)
  • IPSEC DISCONNECTED WHILE WELL CONFIGURED

    2
    0 Votes
    2 Posts
    235 Views
    M
    @isaaclondo09 If only there was logs provided to help us help you
  • Cloudflare MWAN (Ipsec)

    1
    0 Votes
    1 Posts
    180 Views
    No one has replied
  • VPN Issues and odd SADs and SPDs

    1
    0 Votes
    1 Posts
    204 Views
    No one has replied
  • Route through 2 IPSec VPNs

    3
    0 Votes
    3 Posts
    322 Views
    S
    @viragomann Thank you! Do you know if the VPN will disconnect and reconnect if I add the second phase 2? I don't want to cause any disruption when I try it.
  • pfSense IPsec route and source NAT

    3
    0 Votes
    3 Posts
    337 Views
    A
    @viragomann Thank you so much, It's 100% correct I figured it out that's exactly what I have done now. And yes it's only access from one side. Thanks again appreciate your time
  • Ipsec with NAT transversal

    4
    0 Votes
    4 Posts
    382 Views
    V
    @oscar-pulgarin "Any" just accepts any identifier. So it isn't verified. By default IPSec use the interface address, which it is connecting through, as identifier and for incoming connections it expects to see the remote gateway IP. However, since the endpoint gateway is behind a router, IPSec uses the internal IP 10.206.0.14, which your site doesn't expect and drop the connection. But IPSec allows you to state a certain identifier IP. Also there are different identifier types. So if the remote site is behind a NAT router there should be stated its public IP as its identifier. Anyway if you have stated a certain remote gateway, IPSec only allows connection from this IP. So I don't think, "any" for the remote identifier is a security risk here. But you can request them to configure their IPSec properly to use the public IP as identifier, or just enter 10.206.0.14.
  • Access from mobile Ipsec VPN channel, to site-to-site ipsec VPN channel.

    2
    0 Votes
    2 Posts
    232 Views
    V
    @humaxoid None of these. Best method is to add a phase 2 to the site-to-site for the mobile tunnel network. Remember to do this on both sites. Also ensure that the remote network is routed over the mobile IPSec.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.