Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec tunnel established but hosts cannot ping each other

    Scheduled Pinned Locked Moved IPsec
    14 Posts 4 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      michmoor LAYER 8 Rebel Alliance @xAgamemnon
      last edited by michmoor

      @xAgamemnon
      I didn’t mean a screenshot of logs but the actual IPsec logs maybe from console or ssh you can grab it
      Secondly I don’t see any firewall rules. There should be a firewall rule on the IPsec interface I believer. What do the firewall logs show? Any drops?

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      X 1 Reply Last reply Reply Quote 0
      • X
        xAgamemnon @xAgamemnon
        last edited by

        I changed once again to options shown below:
        stablisheddddededeede.png
        tunelowanie ipsec.png
        Now I can ping the WAN and Gateway but host cannot see each other:
        pingowanie 2.png

        1 Reply Last reply Reply Quote 0
        • X
          xAgamemnon @michmoor
          last edited by

          @michmoor Here are the logs:
          Logs IPSEC Site A.txt
          Log IPSEC site B.txt
          Here are the rules on IPSEC:
          ipsec rules.png

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @xAgamemnon
            last edited by

            @xAgamemnon
            Do both host use the pfSense in in their LAN as default gateway?

            Do the hosts themself allow access from outside of their local network?
            Maybe disable their firewalls and reboot them then.

            X 1 Reply Last reply Reply Quote 0
            • X
              xAgamemnon @viragomann
              last edited by xAgamemnon

              @viragomann yes both host use pfsense as default gateway and everything is allowed in firewall as i shown above

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @xAgamemnon
                last edited by

                @xAgamemnon
                I was talking about the firewalls on the host behind pfSense.

                X 1 Reply Last reply Reply Quote 0
                • X
                  xAgamemnon @viragomann
                  last edited by

                  @viragomann That's what I've figured out, after disabling the microsoft defender firewall I can ping between sites without any problem now I just need to add a rule so that this network traffic is allowed. Thanks a lot for help, I don't know why I haven't come across this before

                  V 1 Reply Last reply Reply Quote 1
                  • V
                    viragomann @xAgamemnon
                    last edited by

                    @xAgamemnon
                    The Windows firewall allows basic access like pings from within the local subnet by default, but not from outside.
                    So access normally works as long as it doesn't pass a router.

                    1 Reply Last reply Reply Quote 1
                    • F
                      fcostars @xAgamemnon
                      last edited by

                      @xAgamemnon
                      Estou com o mesmo problema, eu configurei dois pfsenses um matriz e outro filial, mas eu só consigo pingar o pfsense do outro lado e mais nada!
                      dentro da mesma rede pinga normal, mas tanto da matriz como da filial eu nao consigo pingar nenhum micro a não ser o pfsense do outro lado.

                      nas configurações de firewall esta tudo liberado entre os tuneis...

                      alguém tem alguma ideia?

                      F 1 Reply Last reply Reply Quote 0
                      • F
                        fcostars @fcostars
                        last edited by

                        @fcostars Resolvido!
                        Estava clonando configuração ipsec para não digitar tudo novamente e dessa forma o firewall se perde!

                        Segue a dica! Nunca clone uma regra e sim reescreva novamente!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.