Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense 2.5.2 - split-tunneling issue using windows clients

    Scheduled Pinned Locked Moved IPsec
    4 Posts 2 Posters 862 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      serhiil
      last edited by

      Hi,

      I am trying to configure IKEv2 with split-tunneling on pfSense and to use the Windows client. But when I set "Local Network" in Phase 2 to "LAN subnet" or to any "Network", the Windows client gets only the 10.0.0.0/8 route.

      In the Pfsense 2.2.4 - split-tunneling using windows clients - missing route to vpn topic was mentioned:

      • Looking over the IPsec daemon documentation it appears what you are after may not be possible in a way that is both usable and desirable. It's a limitation of the Windows VPN client and not pfSense or IKEv2. The Windows client has no mechanism to receive routes/subnets over IKEv2 other than the VPN tunnel network itself. Unfortunately that's how the Windows client has always worked even with PPTP.

      But when I configure IKEv2 with split-tunneling, for example, on Mikrotik, the Windows client can get multiples routes. So where is the issue with pfSense or the Windows client? Maybe I do something wrong?

      Thanks.

      1 Reply Last reply Reply Quote 0
      • S
        serhiil
        last edited by

        I think I found why the Windows client works with Mikrotik. It's from the Mikrotik documentations:

        • Here is a list of known limitations by popular client software IKEv2 implementations.
          • Windows will always ignore networks received by split-include and request policy with destination 0.0.0.0/0 (TSr). When IPsec-SA is generated, Windows requests DHCP option 249 to which RouterOS will respond with configured split-include networks automatically.

        Did you think to add this feature to pfSense?

        Thanks.

        perikoP 1 Reply Last reply Reply Quote 0
        • perikoP
          periko @serhiil
          last edited by

          @serhiil but what u want to achieve here?

          Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
          www.bajaopensolutions.com
          https://www.facebook.com/BajaOpenSolutions
          Quieres aprender PfSense, visita mi canal de youtube:
          https://www.youtube.com/c/PedroMorenoBOS

          S 1 Reply Last reply Reply Quote 0
          • S
            serhiil @periko
            last edited by

            @periko I would like to know if it is planned to add route pushing to Windows clients using DHCP option?

            Thanks.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.