IPSEC VPN and windows server 2019
-
Hello every one!
Need to find out if after configuring IPSEC VPN on pfsense firewall, do I still also need to configure windows server 2019 remote access or no need to do anything at windows server ? Or even disable that feature on the server?I can see that my VPN pass Tru the firewall but doesn't get connected it only ends as disconnected from the client computer....I wonder if the remote access feature on the server also has to be configured in order for pfsense IPSec vpn actually get connected to the server
I would think that by setting up the vpn service on the firewall it would actually see the client as if it were connected locally on the network
Thanks in advance
-
@rub75f
Not clear what the IPSec on the Windows server has to do with that one on pfSense.
Can you explain your setup a bit more detailed, please? -
@viragomann
Is not the IPsec on windows server but the Remote Access Service.Ok so this is what I'm trying to do:
I have a windows 2019 server and a PFsense firewall/router. I want to create a VPN connection so when ever I need to access my network, especially my server, from a difference network meaning outside my office or on the go on my mobile device I can connect to my server.I followed the guide on pfsense website about deploying IPSEC vpn, configured everything as said on the guide, even the NAT and portforwarding on the pfsense firewall and I can see connection passing through the firewall but it never gets to the connected point on my mobile device (cellphone).
When I enter my credentials on my VPN mobile device setup it only says 'connecting' and after about a minute it says disconnected.
So this is why I need to know if after setting up the IPsec VPN on pfsense, do I still need to do anything on the server side in order for my mobile device to connect to the windows server machine??
I was assuming that setting up the ipsec on pfsense everytime we VPN to the firewall from outside the network, pfsense would look and treat the connection as if I was in my office network so I would gain access to my server.But so far when I try to connect to my server via VPN, the connection never gets connected. So that's I'm asking if I need to also configure remote access service in my server or not?
Thanks in advance
-
@rub75f
So you set up an IPSec server on pfSense with intention to connect to internal devices. No, there should be no more to do.
However, it seems your mobile device cannot connect.So do you have a public IP on pfSense WAN?
Or is there a router in front of it? If so how did you set up NAT on the router?Do you have a static public IP or a dynamic?
On pfSense WAN you will have a firewall rule allowing the IPSec packets. So check if any packet hit the rule.