• Mobile Clients with a entire Subnet

    5
    0 Votes
    5 Posts
    1k Views
    K
    @blackbinary Hey This is possible, but you must make changes to the PFsense configuration files (responder side) As a result of these changes, PFSense will create a config file (ipsec.conf) that will allow strongswan to accept connections from any ip address Here is an example of how it looks in practice after the changes In the settings section of Remote Gateway you enter "any" and the necessary config is ready [image: 1554120408570-c2a5f51c-aaa5-4e48-9629-6de183f1a0e5-image-resized.png] If you write me in the chat your email, I'll send you an email with all instructions
  • TCP issue inside the tunnel

    12
    0 Votes
    12 Posts
    2k Views
    M
    Hello Just noticed it breaks large packets of UDP :( hopefully we will get fix soon. https://redmine.pfsense.org/issues/7801
  • Ipsec Problems with Radius over the tunnel for WIFI hotspots

    1
    0 Votes
    1 Posts
    217 Views
    No one has replied
  • Problems with IPSec from China to United States

    1
    0 Votes
    1 Posts
    304 Views
    No one has replied
  • IPSec to Cisco ASR 1013

    4
    0 Votes
    4 Posts
    1k Views
    T
    @Konstanti Ya, I can't tell you how many times I verified the IPSec settings Magically, the connection was established last night as I left it on while doing some other work. When I returned to have another look, the connection was made. I tried this current configuration multiple times to no avail, so I am baffled as to what the resolution was I'm booking a meeting with a guy at the other side to start pulling parts and pieces apart to determine the issue One thing I noticed is that the initial attempts to connect were using port 4500 and the established tunnel is on 500 (I have no firewall logs blocking this and I have rules on WAN in place explicitly allowing UDP 500/4500 and ESP. Perhaps their end isn't liking the 4500 (they told me they are good with the UDP 4500 mind you) Sort of feels like Cisco just not wanting to play nice in the sandbox with the other kids. I'll update with any resolution(s) or comments here
  • Problems with traffic in VPN tunnel

    4
    0 Votes
    4 Posts
    770 Views
    K
    @Juan-Carlos-Gtz Hey You're only allowed TCP on the interface IPSEC Mex 2. Other protocols are prohibited. In order to use ping you need to enable ICMP.
  • Mobile Clients not sending all traffic via VPN

    ipsec vpn
    1
    0 Votes
    1 Posts
    324 Views
    No one has replied
  • My first routed ipsec environment, tunnels keep failing

    1
    0 Votes
    1 Posts
    234 Views
    No one has replied
  • Failback IPsec Tunnel

    1
    0 Votes
    1 Posts
    364 Views
    No one has replied
  • IPSEC's VPN can't PING the host network and vice versa

    ipsec vpn client ping ssh
    1
    0 Votes
    1 Posts
    652 Views
    No one has replied
  • Routing between VPN Client and VPN tunnel

    7
    0 Votes
    7 Posts
    1k Views
    I
    [image: 1553357748255-pfs2.jpg] [image: 1553357756563-azurepfs.png]
  • FW Rules for VTI interfaces

    9
    0 Votes
    9 Posts
    2k Views
    DerelictD
    Then post what you have because it most certainly does work.
  • Advertise specific routes (( not 0.0.0.0/0 )) via bgpd

    2
    1
    0 Votes
    2 Posts
    263 Views
    NogBadTheBadN
    Might be better to use FRR in place of OpenBGP.
  • pfSense AWS VPN Dropout Every Month

    Moved
    3
    0 Votes
    3 Posts
    510 Views
    galda01G
    Excellent questions. I will check when it happens again. I appreciate you replying so quickly. -Andrew G
  • Routed IPSec Tunnel VTI Interface is down

    1
    0 Votes
    1 Posts
    254 Views
    No one has replied
  • IPSEC site to site Tunnel - cannot ping beyond Pfsene

    4
    2
    0 Votes
    4 Posts
    533 Views
    A
    Removed all config and re did all config on both pfsense and Cisco and it now works. Dont know why it works as I din't change any settings....
  • IPsec Mobile Client send all traffic to internet

    1
    0 Votes
    1 Posts
    228 Views
    No one has replied
  • IPSEC Tunnel doesn't disable when disabled.

    1
    0 Votes
    1 Posts
    215 Views
    No one has replied
  • IPSec phase 2 not running initiating behind a NATed router

    1
    0 Votes
    1 Posts
    268 Views
    No one has replied
  • failing to connect with strongSwan

    1
    1
    0 Votes
    1 Posts
    555 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.