• Users are being disconnected at a certain time

    4
    0 Votes
    4 Posts
    488 Views
    GertjanG
    @movIT You are probably limited by the GUI. You could go here : Status > System Logs > Settings and change [image: 1725431946352-c5dad0b9-bcbc-4136-8867-484d78c846fc-image.png] to something a bit bigger. Check also this : [image: 1725431976584-4280c79f-7433-4ea4-b1c1-6f317c100f08-image.png] where you can set overall log file size. If you have many G bytes to spare, you can make these files a bit bigger. On very small devices : be carefull. But you can also apply the "IT" way : you don't care about GUI ... go native access right away. Go to the source. Use the console, or, like everybody else, use the SSH access, and look her /var/log/ as that is the place where logs are stored on nearly every "computer" on planet earth. You'll find the system.log file. Btw : typically, I have 20-30 lines a day in the System log file. So "only the last 5 minutes worth" is pretty strange : what is happening in there that your pfSense logs that much ? ? Massive logs == normally : an indication something not-ok is going on.
  • Azure pfsense one way traffic

    1
    0 Votes
    1 Posts
    190 Views
    No one has replied
  • IPSEC port forwarding issue

    4
    1
    0 Votes
    4 Posts
    504 Views
    V
    @netgate-powdered559 And the page works if you access it directly from the lab and from the internet if the latter is even possible?
  • IPSec is very slow between two pfsense routers

    40
    6
    0 Votes
    40 Posts
    13k Views
    P
    @optimusprime I apply in this option: [image: 1724847936234-d15f6b0e-dc4f-4612-9973-a628ee43d373-image.png] [image: 1724847911969-8d1c5b5b-af44-4ef6-aa5f-1b5f3cfd3100-image.png]
  • Phase 2 Entries for IPSec Multi-Site Hub and Spoke

    2
    1
    0 Votes
    2 Posts
    269 Views
    V
    @bkhiatt Are all phase 2 shown up as connected in Status > IPSec? Please post Status > IPsec > SPDs of all three sites.
  • MacOS VPN import

    5
    1 Votes
    5 Posts
    580 Views
    Sergei_ShablovskyS
    @SteveITS said in MacOS VPN import: Most of my Mac experience was on System 6/7. :) The double click started the import but didn't open anything. Ouch! Really ??? So welcome and try “the *nix with a human face”! ;)
  • IPSEC DISCONNECTED WHILE WELL CONFIGURED

    2
    1
    0 Votes
    2 Posts
    296 Views
    M
    @isaaclondo09 If only there was logs provided to help us help you
  • Cloudflare MWAN (Ipsec)

    1
    0 Votes
    1 Posts
    192 Views
    No one has replied
  • VPN Issues and odd SADs and SPDs

    1
    0 Votes
    1 Posts
    217 Views
    No one has replied
  • Route through 2 IPSec VPNs

    3
    0 Votes
    3 Posts
    350 Views
    S
    @viragomann Thank you! Do you know if the VPN will disconnect and reconnect if I add the second phase 2? I don't want to cause any disruption when I try it.
  • pfSense IPsec route and source NAT

    3
    0 Votes
    3 Posts
    386 Views
    A
    @viragomann Thank you so much, It's 100% correct I figured it out that's exactly what I have done now. And yes it's only access from one side. Thanks again appreciate your time
  • Ipsec with NAT transversal

    4
    0 Votes
    4 Posts
    430 Views
    V
    @oscar-pulgarin "Any" just accepts any identifier. So it isn't verified. By default IPSec use the interface address, which it is connecting through, as identifier and for incoming connections it expects to see the remote gateway IP. However, since the endpoint gateway is behind a router, IPSec uses the internal IP 10.206.0.14, which your site doesn't expect and drop the connection. But IPSec allows you to state a certain identifier IP. Also there are different identifier types. So if the remote site is behind a NAT router there should be stated its public IP as its identifier. Anyway if you have stated a certain remote gateway, IPSec only allows connection from this IP. So I don't think, "any" for the remote identifier is a security risk here. But you can request them to configure their IPSec properly to use the public IP as identifier, or just enter 10.206.0.14.
  • Access from mobile Ipsec VPN channel, to site-to-site ipsec VPN channel.

    2
    0 Votes
    2 Posts
    253 Views
    V
    @humaxoid None of these. Best method is to add a phase 2 to the site-to-site for the mobile tunnel network. Remember to do this on both sites. Also ensure that the remote network is routed over the mobile IPSec.
  • pfSense behind nat, not connection/response to Fortinet

    2
    8
    0 Votes
    2 Posts
    292 Views
    M
    I also noticed this Why the ID says "any identifier" if I established the IP in both? [image: 1723251693398-d9a3b80c-6d46-495e-abc2-20f99c573b89-image.png]
  • IPSEC: requests: list-sas then disconnect

    2
    0 Votes
    2 Posts
    592 Views
    keyserK
    @datacare There are no responses from the opposite end. Remeber IKE uses UDP, and can transmit several packets it considers “data” without any preceeding “connection” being made as with TCP. Notice there are no packets recieved from the other end - so you need to investigate that, and why :-)
  • IPSec Status shows Local/Remote as /0[esp]

    1
    1
    0 Votes
    1 Posts
    180 Views
    No one has replied
  • Ipsec interface assignment

    1
    2
    0 Votes
    1 Posts
    166 Views
    No one has replied
  • IPSec Random Disconnections

    1
    1 Votes
    1 Posts
    178 Views
    No one has replied
  • Ipsec and android

    11
    2
    1 Votes
    11 Posts
    936 Views
    A
    @planedrop don't load pn the ipsec tunnel.
  • IPSec tunnel issue

    1
    0 Votes
    1 Posts
    192 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.