Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ipsec tunnel going down

    Scheduled Pinned Locked Moved IPsec
    8 Posts 3 Posters 474 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      moisesdasilvadeoliveira
      last edited by

      This post is deleted!
      M 2 Replies Last reply Reply Quote 0
      • M
        moisesdasilvadeoliveira @moisesdasilvadeoliveira
        last edited by

        This post is deleted!
        1 Reply Last reply Reply Quote 0
        • M
          moisesdasilvadeoliveira @moisesdasilvadeoliveira
          last edited by

          @moisesdasilvadeoliveira
          Dear,

          Would anyone have any ideas?

          M 1 Reply Last reply Reply Quote 0
          • M
            michmoor LAYER 8 Rebel Alliance @moisesdasilvadeoliveira
            last edited by

            @moisesdasilvadeoliveira you deleted your posts….

            Firewall: NetGate,Palo Alto-VM,Juniper SRX
            Routing: Juniper, Arista, Cisco
            Switching: Juniper, Arista, Cisco
            Wireless: Unifi, Aruba IAP
            JNCIP,CCNP Enterprise

            M 2 Replies Last reply Reply Quote 0
            • M
              moisesdasilvadeoliveira @michmoor
              last edited by

              @michmoor
              Sorry

              Dear

              I have 2 problems with my ipsec. It is worth mentioning that my pfsense is in the cloud with only one wan (Subnet 1) and I have a network that comes from openvpn (Subnet 2).

              Problem 1.
              If my phase two tunnels go down, I can't generate traffic for those tunnels to get up again. The tunnels are only up again, if my client generates traffic through his network.
              With that I had the idea of enabling the function "Automatically ping host" and "Keep Alive"

              Problem 2.
              Enabling the two functions of "Automatically ping host" and "Keep Alive", for subnet 1 (My wan), it generates keepalives and keeps my tunnels up from subnet 1. But in the case of my subnet 2 (Openvpn) , I see that the keepalive is not being sent, so my tunnels are down

              I believe that if I have an option for problem 1, it already solves my problem, because I don't need to ask the client to generate traffic on his side.
              But if not possible, how can I generate keepalive for subnet 2.

              OBS.: Subnet 1 has monitoring traffic, so it will probably always stay up due to monitoring traffic. Subnet 2, on the other hand, will not have constant traffic, since it will be used by employees to access via openvpn to access the closed structure via ipsec (vpn Site-to-Site)

              Thanks

              V 1 Reply Last reply Reply Quote 0
              • M
                moisesdasilvadeoliveira @michmoor
                last edited by

                Would anyone have any ideas?

                1 Reply Last reply Reply Quote 0
                • V
                  viragomann @moisesdasilvadeoliveira
                  last edited by

                  @moisesdasilvadeoliveira said in ipsec tunnel going down:

                  With that I had the idea of enabling the function "Automatically ping host" and "Keep Alive"

                  Did you do this?

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    moisesdasilvadeoliveira @viragomann
                    last edited by

                    @viragomann yes, i did this setting, but it had no effect.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.